Malicious PDF — malware analysis report

Static analysis result for SHA-256 c5a023077e736109…

MALICIOUS

PDF

120.3 KB Created: 2022-07-05 03:18:15 +00:00 Authoring application: kamala (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 2308294090540837994f0d31d9031ec0 SHA-1: 2ee5fc1cdaf241a1d1857020b0ad542887a79888 SHA-256: c5a023077e7361096e090e06e2ab3cd653ebcc6648682081942305e2186dadf9
84 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which point to websites offering cracked software, specifically Adobe Photoshop. The heuristic 'PDF_SEO_LINK_FARM' indicates a deliberate attempt to create a link farm, likely for SEO manipulation or to distribute malicious payloads. The presence of a direct IP address link further suggests a potentially untrusted source.

Machine Learning

  • Nyx PDF Classifier clean score 0.0378

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://signforcover.com/centrifuge.ZG93bmxvYWR8SjdjTkRscE1YeDhNVFkxTmprNE1UVXdOSHg4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk/briggs=colby/QWRvYmUgUGhvdG9zaG9wIDIwMjIgKFZlcnNpb24gMjMuMSkQWR=donington/basis
    • https://futurestrongacademy.com/wp-content/uploads/2022/07/Photoshop_CC_2014_Crack_Mega__Patch_With_Serial_Key_Free_Download.pdf
    • http://joshuatestwebsite.com/adobe-photoshop-2020-free-x64/
    • https://polar-retreat-63165.herokuapp.com/Photoshop_2021_Version_2200.pdf
    • https://bbv-web1.de/wirfuerboh_brett/advert/adobe-photoshop-cs6-activation-key-updated-2022/
    • https://powerful-meadow-91983.herokuapp.com/Photoshop_CC_2015_version_18.pdf
    • https://cameraitacina.com/en/system/files/webform/feedback/adobe-photoshop-2021-version-22_19.pdf
    • https://aghadeergroup.com/2022/07/05/adobe-photoshop-2021-version-22-5-crack-serial-number-with-key/
    • https://ocurme.com/photoshop-2022-version-23-keygen-crack-serial-key-activation-code-with-keygen-download-pc-windows/
    • https://gaming-walker.com/upload/files/2022/07/UnfPMJ6rRS5U9PUPIgMb_05_63ac2c6f4184aadfe2c8f6ef29e67f89_file.pdf
    • https://www.streetbutlers.com/wp-content/uploads/2022/07/Adobe_Photoshop_CS4.pdf
    • http://18.138.249.74/upload/files/2022/07/vb9bgjFtbSDQAVk8oBo6_05_2e24c2b7ceb4f18c6bbd5ccc02597661_file.pdf
    • http://cipheadquarters.com/?p=27804
    • http://findmallorca.com/adobe-photoshop-2021-version-22-5-1-keygen-crack-setup-with-serial-key-win-mac-2022-latest/
    • https://loskutbox.ru/wp-content/uploads/2022/07/Adobe_Photoshop_2021_version_22_Download_PCWindows_April2022.pdf
    • https://ceza.gov.ph/system/files/webform/resume/adobe-photoshop-2020-version-21_0.pdf
    • https://supportlocalbiz.info/wp-content/uploads/2022/07/wondpeve.pdf
    • https://lutce.ru/wp-content/uploads/2022/07/samjam.pdf
    • https://vdsproductions.nl/photoshop-2021-version-22-2-win-mac-updated-2022/
    • http://www.b3llaphotographyblog.com/wp-content/uploads/2022/07/macabry.pdf
    • https://www.bigaticaret.com/wp-content/uploads/2022/07/olumai.pdf
    • https://nameme.ie/adobe-photoshop-2022-version-23-1-1-incl-product-key-download-for-pc-2/
    • https://polar-plains-65959.herokuapp.com/Adobe_Photoshop.pdf
    • http://ursgift.com/?p=17214
    • http://evergreenpearl.com/?p=4286
    • https://techadarsh.com/wp-content/uploads/2022/07/blesree.pdf
    • https://likesmeet.com/upload/files/2022/07/B6oZe6HLV4eSCVFboTMu_05_af3c2029e244fa7fe996096e1bbf0349_file.pdf
    • https://www.cakeresume.com/portfolios/adobe-photoshop-cc-2015-version-18-keygen-downlo
    • https://wakelet.com/wake/hpXvcs7y6AnsPpwJ_1Cn_
    • https://stenhasniweele.wixsite.com/anorerar/post/photoshop-cc-2018-download-x64-april-2022
    • https://www.cakeresume.com/portfolios/photoshop-2022-version-23-0-serial-key-free-32
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/