Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba8902701f55b114…

MALICIOUS

PDF

124.3 KB Created: 2022-06-10 05:41:56 +02:00 Authoring application: moreprop (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: f71258a9a8d5c7e558ff47a80ced1300 SHA-1: 2e7b89a5f1b3d8b88af21b6395c9c2350f6b176a SHA-256: ba8902701f55b114315c58f930cc138fb6e12d5a2866e17ec160bd4b5fc87ad2
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified as a link farm. One of the primary links, http://evacdir.com/..., points to a suspicious URL that likely hosts malicious content. The presence of numerous links suggests an attempt to distribute malware or conduct phishing through SEO poisoning or by overwhelming the user with choices.

Machine Learning

  • Nyx PDF Classifier clean score 0.0213

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/?activations=/churrascaria/hostelworld/TWljcm9zb2Z0IE9mZmljZSAyMDA3IFN3ZWRpc2ggVXRvcnJlbnQTWl.prescheduled.ZG93bmxvYWR8cHY2TjJNemJYeDhNVFkxTkRjNE1EZzNPWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.visuals
    • https://www.plori-sifnos.gr/vcds-lite-free-crack-keygen-site/
    • https://2figureout.com/via-vt6306-windows-7-driver-download/
    • https://www.valenciacfacademyitaly.com/wp-content/uploads/2022/06/odejav.pdf
    • https://www.bizzmreza.com/wp-content/uploads/2022/06/kashi_choo_mantar_the_mask_dubbed_in_punjabi_full_movie.pdf
    • https://4j90.com/etka-7-4-download-torrent-verified/
    • http://fokusparlemen.id/?p=17617
    • https://zemsl.org/wp-content/uploads/2022/06/esbdeve.pdf
    • https://newsbaki.com/wp-content/uploads/2022/06/Manan_Prakashan_Books_Mcom_Pdf_Free_VERIFIED.pdf
    • https://eleven11cpa.com/wp-content/uploads/2022/06/Natalie_13_Industrial_De_Novo.pdf
    • https://www.modifind.com/offroad/advert/instant-roof-pro-work/
    • http://www.ecomsrl.it/wondershare-quiz-creator-4-5-0-full-serial-key/
    • https://northshorerealtysanpancho.com/advert/programming-in-c-reema-thareja-pdf-35-free/
    • http://www.eztkerested.hu/upload/files/2022/06/RXIZpsrIPYqMVePI38jB_10_60e79a566a5ba2bdc7000ca7b9485430_file.pdf
    • https://ipa-softwareentwicklung.de/wp-content/uploads/2022/06/anjesere.pdf
    • https://thecvsystem.com/wp-content/uploads/2022/06/meluzzi.pdf
    • http://www.7daystobalance.com/advert/mursit5programiindiryukle/
    • https://mugstand.com/?p=3070
    • https://beautysecretskincarespa.com/2022/06/10/big-hero-6-tamil-dubbed-movie-842/
    • https://www.bryophyteportal.org/portal/checklists/checklist.php?clid=18607
    • https://vizitagr.com/wp-content/uploads/2022/06/Wilcom_Embroidery_Studio_E4_Torrent_FULL.pdf
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off000012c1.bin
a217f12862e0ff75203bdd4136ca0d68471050be46bb09aed5306898926ffdd4
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x12C1 120140 bytes