Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7b9525dd1f14a4b…

MALICIOUS

PDF

119.5 KB Created: 2022-07-08 05:11:57 +00:00 Authoring application: cardre (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 53c9192bf2cc1e82a5fca2f4a1c2d560 SHA-1: f758472a761552847bc74a2012241eaf5eef1f96 SHA-256: c7b9525dd1f14a4be0f323db5ff612a93e13fbb3778a7de6772597e5a58de729
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. One of these links, http://bestsmartfind.com/inhalations/..., appears to be a download URL. The presence of a link farm suggests an attempt to distribute malicious content or engage in SEO abuse for traffic generation.

Machine Learning

  • Nyx PDF Classifier clean score 0.0088

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bestsmartfind.com/inhalations/ZG93bmxvYWR8cmUzWjIxMGFIeDhNVFkxTnpFNE5qazFOWHg4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk/pumps?indomitable&netpost=RnJlZSBjcmFjayBQTEFYSVMgMkQgVjkuNTARnJ
    • https://scoalacunoasterii.ro/wp-content/uploads/2022/07/kaitkala.pdf
    • http://trzyosly.pl/wp-content/uploads/2022/07/Sendblaster_2_Serial_Keyepub.pdf
    • http://www.be-art.pl/wp-content/uploads/2022/07/brauer_neue_font_portable.pdf
    • https://himoin.com/upload/files/2022/07/6x3UNOM7PnKie6elf8V7_08_490e23a7b576a877b8771fbeefd622d2_file.pdf
    • https://www.2tmstudios.com/symantec-norton-utilities-16-0-2-53-crack-for-windows-full/
    • https://alafdaljo.com/busou-shinki-battle-masters-mk2-w-dlc-exclusive/
    • https://www.bigdawgusa.com/gann-wheel-of-24-software-2021-downloadl/
    • https://xn--80aagyardii6h.xn--p1ai/matematikos-vadovelis-11-klasei-pdf-free-exclusive/
    • https://www.theblender.it/1920-evil-returns-1080p-hindi/
    • https://elsm.ch/advert/downloadkeygenxforceforautocadmechanical2018keygen-repack/
    • https://cuisinefavorits.online/media-player-for_dum-laga-ke-haisha/
    • https://www.reperiohumancapital.com/system/files/webform/yekurap383.pdf
    • https://our-study.com/upload/files/2022/07/aQYkQqXwFBqG2aeqfQMQ_08_549fb5fd449d5d873c387dca4fa58369_file.pdf
    • http://hotelthequeen.it/?p=46970
    • https://netgork.com/upload/files/2022/07/iAafJRKeQe8DcU4OjnwO_08_490e23a7b576a877b8771fbeefd622d2_file.pdf
    • http://mulfiya.com/grass-valley-canopus-edius-652-x64-x86torrent-5-2/
    • https://rwbible.com/football-manager-2013-crack-patch-13-3-3-by-skidrow-new/
    • http://teegroup.net/?p=13595
    • https://streamcolors.com/en/licence-logiciel-eobd-facile-crack-exclusive/
    • https://himoin.com/upload/files/2022/07/6x3UNOM7PnKie6elf8V7_08_490e23a7b576a877b8771fbeefd622d2
    • https://our-study.com/upload/files/2022/07/aQYkQqXwFBqG2aeqfQMQ_08_549fb5fd449d5d873c387dca4fa58
    • https://netgork.com/upload/files/2022/07/iAafJRKeQe8DcU4OjnwO_08_490e23a7b576a877b8771fbeefd622d
    • https://wakelet.com/wake/yeZ7hARSoF9bUXL-v2tTw
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/