Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2ef25d1e145df16…

MALICIOUS

PDF

137.9 KB Created: 2022-07-05 16:12:08 +00:00 Authoring application: wadlraf (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 252070df87bc998feb8f7441b949d170 SHA-1: 70cab9a7cdf377271b25eaae82db06851887f303 SHA-256: c2ef25d1e145df16d8e78d9b8b643e42e1e05c090e19ce5d1b8108ab81220b1f
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF document contains a large number of external links, many of which appear to be SEO-optimized and related to 'FIFA 22'. One embedded URL, http://godsearchs.com/tools/, is directly associated with a malicious payload. The document's structure and content suggest it is designed to drive traffic to these malicious sites, likely for malware distribution or phishing.

Machine Learning

  • Nyx PDF Classifier clean score 0.0064

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://godsearchs.com/tools/?anatembea=RmlmYSAyMgRml&habanera=systemsclean/ZG93bmxvYWR8NEN3Ym1jNWZId3hOalUzTURNMk1qSXpmSHd5TlRjMGZId29UU2tnY21WaFpDMWliRzluSUZ0R1lYTjBJRWRGVGww
    • https://tchatche.ci/upload/files/2022/07/EbdosrwwqT3N7WHW48kF_05_f8a649bd5dba39d6d8426e6c6c7cdccc_file.pdf
    • https://noshamewithself.com/upload/files/2022/07/vUQbFHE716ochyNr7VJL_05_f8a649bd5dba39d6d8426e6c6c7cdccc_file.pdf
    • https://telebook.app/upload/files/2022/07/mCf28Duu8APcdRLtnrDR_05_83f6671ed745835274a27423d1c2c1db_file.pdf
    • https://www.cameraitacina.com/en/system/files/webform/feedback/fifa-22_160.pdf
    • https://righttoexpress.com/upload/files/2022/07/ofeq7DsBf5Oe4VmmAisb_05_83f6671ed745835274a27423d1c2c1db_file.pdf
    • https://www.firstusfinance.com/fifa-22-crack-with-serial-number/
    • http://www.rti-evaluation.org/fifa-22-with-key-free-download-updated/
    • https://nailpersona.com/wp-content/uploads/2022/07/fifa_22.pdf
    • https://ayoikut.com/advert/fifa-22-crack-exe-file-free-registration-code/
    • https://voiccing.com/upload/files/2022/07/OKG3IMwxs8vCGte8UEI6_05_83f6671ed745835274a27423d1c2c1db_file.pdf
    • https://liquidonetransfer.com/wp-content/uploads/2022/07/Fifa_22_Mem_Patch___Free_April2022.pdf
    • https://en-med.tau.ac.il/sites/med_en.tau.ac.il/files/media_server/medicine/SICF_Servicse
    • https://connectingner.com/2022/07/05/fifa-22-keygen-exe-download-2022/
    • https://thefuturegoal.com/upload/files/2022/07/TqMmWpM4gXUQA5ZVhTCz_05_75c970a131bac18d214a76c29e49a1ed_file.pdf
    • https://poliestudios.org/campus2022/blog/index.php?entryid=3044
    • https://northshorerealtysanpancho.com/advert/fifa-22-keygen-free-download-for-pc/
    • http://www.giffa.ru/computerscomputer-certification/fifa-22-keygenerator-mac-win-latest/
    • https://www.lebanontownhall.org/sites/g/files/vyhlif4596/f/pages/birth_record_request.pdf
    • https://wmich.edu/system/files/webform/Fifa-22_19.pdf
    • https://www.colorado.edu/ocg/sites/default/files/webform/fifa-22.pdf
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/