Malicious PDF — malware analysis report

Static analysis result for SHA-256 cc7304aacfbae8b0…

MALICIOUS

PDF

125.3 KB Created: 2022-07-05 02:23:40 +00:00 Authoring application: gayodd (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 5ee73b83e0337e051d63b29d92fdf530 SHA-1: d62afc13eb60c06c77370d424bd43b20eee9b034 SHA-256: cc7304aacfbae8b0a8c541568607a7e5b56450f5d4bc7c71bdc5f4a0abb84fcd
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. One of these links, http://blogbasters.com/ZG93bmxvYWR8c3A4TW5Kak5IeDhNVFkxTmprNE1UVXdOSHg4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk/croutons?perak.delegation=QWRvYmUgUGhvdG9zaG9wIDIwMjEgKHZlcnNpb24gMjIpQWR&ignoble.microcapsules=pest, appears to be a download URL. This suggests the document is designed to trick users into visiting these links and potentially downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier clean score 0.0247

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://blogbasters.com/ZG93bmxvYWR8c3A4TW5Kak5IeDhNVFkxTmprNE1UVXdOSHg4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk/croutons?perak.delegation=QWRvYmUgUGhvdG9zaG9wIDIwMjEgKHZlcnNpb24gMjIpQWR&ignoble.microcapsules=pest
    • https://tunneldeconversion.com/wp-content/uploads/2022/07/rosiyel.pdf
    • https://www.accurateperforating.com/sites/default/files/webform/Adobe-Photoshop-2021-Version-2243.pdf
    • https://miraclestripbass.com/wp/advert/photoshop-cs6-2022/
    • https://tgmcn.com/photoshop-cc-2019-version-20-keygen-exe/
    • https://www.corsisj2000.it/photoshop-cc-2015-hack-free-for-windows/
    • https://recycledsigns.com/advert/adobe-photoshop-2022-version-23-2-keygen-exe-lifetime-activation-code-win-mac-final-2022/
    • http://www.b3llaphotographyblog.com/adobe-photoshop-cs6-free/
    • https://mysterious-ravine-70034.herokuapp.com/daridae.pdf
    • https://gyllendal.com/wp-content/uploads/2022/07/Adobe_Photoshop_CS3.pdf
    • https://citywharf.cn/adobe-photoshop-2022-version-23-1-1-keygen-crack-setup-full-version-download-3264bit/
    • https://doitory.com/photoshop-2022-version-23-0-hacked-download-for-windows/
    • https://www.daikin.com.au/sites/default/files/webform/resume/ellamb800.pdf
    • https://www.reperiohumancapital.com/system/files/webform/Adobe-Photoshop-CC-2019-version-20_3.pdf
    • https://www.fooos.fun/social/upload/files/2022/07/fOCoIftZ2ngeLbQ8n7jV_05_d3c46a0c5c1307e4c5e8fd81e2b3ce4e_file.pdf
    • https://sharingourwealth.com/social/upload/files/2022/07/jtycw3BxBqok72InIzwA_05_06a34d095b2054ffc4755bcd99162c46_file.pdf
    • https://www.jatjagran.com/wp-content/uploads/Photoshop.pdf
    • https://eat-now.no/wp-content/uploads/2022/07/Adobe_Photoshop_2021_Version_2243.pdf
    • https://workplace.vidcloud.io/social/upload/files/2022/07/Xl9EhM6iLaQRuJtwsC4c_05_1f965b88355ce93f9b7e9e9d98cd2be3_file.pdf
    • https://fierce-tundra-44618.herokuapp.com/Photoshop_2021_Version_2211.pdf
    • https://kaalama.org/upload/files/2022/07/BqV7VkcITJFvIEmPUvRq_05_d157424c427ba9454143d28c0a8d41a4_file.pdf
    • http://kampungkbpucangsawit.com/?p=3138
    • https://nameme.ie/photoshop-2021-version-22-0-1-keygen-2022/
    • https://africakesse.com/adobe-photoshop-cc-2015-product-key-and-xforce-keygen-license-key-latest-2022/
    • https://skatesquad.com/upload/files/2022/07/MTShAMGWncjP7DrgDrEo_05_06a34d095b2054ffc4755bcd99162c46_file.pdf
    • https://www.crokergrain.com.au/system/files/webform/Photoshop-2021-version-22.pdf
    • https://www.marlowropes.com/system/files/webform/ulylead740.pdf
    • https://inobee.com/upload/files/2022/07/hKucM9DUKZFloItb57jX_05_d157424c427ba9454143d28c0a8d41a4_file.pdf
    • https://www.plori-sifnos.gr/adobe-photoshop-cs5-full-version-april-2022/
    • https://www.accurateperforating.com/sites/default/files/webform/Adobe-
    • https://recycledsigns.com/advert/adobe-photoshop-2022-version-23-2-keygen-exe-lifetime-activation-
    • https://citywharf.cn/adobe-photoshop-2022-version-23-1-1-keygen-crack-setup-full-version-
    • https://www.reperiohumancapital.com/system/files/webform/Adobe-Photoshop-
    • https://www.fooos.fun/social/upload/files/2022/07/fOCoIftZ2ngeLbQ8n7jV_05_d3c46a0c5c1307e4c5e
    • https://sharingourwealth.com/social/upload/files/2022/07/jtycw3BxBqok72InIzwA_05_06a34d095b205
    • https://workplace.vidcloud.io/social/upload/files/2022/07/Xl9EhM6iLaQRuJtwsC4c_05_1f965b88355ce
    • https://kaalama.org/upload/files/2022/07/BqV7VkcITJFvIEmPUvRq_05_d157424c427ba9454143d28c0
    • https://africakesse.com/adobe-photoshop-cc-2015-product-key-and-xforce-keygen-license-key-
    • https://skatesquad.com/upload/files/2022/07/MTShAMGWncjP7DrgDrEo_05_06a34d095b2054ffc4755
    • https://inobee.com/upload/files/2022/07/hKucM9DUKZFloItb57jX_05_d157424c427ba9454143d28c0a
    • https://leadership.oregonstate.edu/sites/leadership.oregonstate.edu/files/principles-final2.pdf
    • https://wakelet.com/wake/cnPEiQiyCOEq-azYWMmZJ
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    +2 more URL(s)