Malicious PDF — malware analysis report

Static analysis result for SHA-256 ccb975fdb5eed1bf…

MALICIOUS

PDF

124.5 KB Created: 2022-07-07 23:15:57 +00:00 Authoring application: adenark (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 0de04d18f346baa30fa2ea185da18820 SHA-1: c330a0ea6a3c748fd5da72ad3af3ad97c508c6bb SHA-256: ccb975fdb5eed1bff497c5c7c3b4e0f1daebbca85f5b23e411be552616d22264
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a tactic to drive traffic to potentially malicious websites. One such URL is http://dormister.com/spectator/harware.ornish.ZG93bmxvYWR8VzFuTjNWcGQzeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/bGlicm8gcHJpbmNpcGlvcyBkZSBjb250YWJpbGlkYWQgZGUgYmVybmFyZCBoYXJnYWRvbiBwZGYgMTkbGl/portability/touched. The document body is heavily obfuscated and does not provide clear textual lures, but the presence of numerous links points towards a malicious distribution or redirection scheme.

Machine Learning

  • Nyx PDF Classifier clean score 0.0070

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dormister.com/spectator/harware.ornish.ZG93bmxvYWR8VzFuTjNWcGQzeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/bGlicm8gcHJpbmNpcGlvcyBkZSBjb250YWJpbGlkYWQgZGUgYmVybmFyZCBoYXJnYWRvbiBwZGYgMTkbGl/portability/touched
    • https://aalcovid19.org/click-and-learn-didi-360-cd-crack-__hot__/
    • http://domainmeans.com/?p=19088
    • https://copasulassessoria.com.br/advert/fallout-new-vegas-top-download-100mb-pc/
    • https://ex0-sys.app/upload/files/2022/07/NibCO8okCrxtDUKHxe69_07_67bd9f113ae85f24b92ff9b4833cc032_file.pdf
    • https://in-loving-memory.online/nch-software-serial-number-crack-software-upd/
    • https://kurditi.com/upload/files/2022/07/69sk1eRCd7BmTw8W2Otx_07_dd13cb4f5179fa1ab75da13db349dca8_file.pdf
    • https://chuchoola.fun/?u=k8pp605
    • https://news.mtkenya.co.ke/advert/mega-man-legacy-collection-crack-download-free-pc-__top__/
    • https://www.agisante.com/sites/default/files/webform/vynhel979.pdf
    • https://mevoydecasa.es/sacred-gold-gog-v-2-0-0-4-cheat-codes/
    • https://alternativeconversation.com/upload/files/2022/07/RnFPdacDLsPIoEpoj4ab_07_dd13cb4f5179fa1ab75da13db349dca8_file.pdf
    • https://aposhop-online.de/wp-content/uploads/2022/07/WinToUSB_Enterprise_28_Key_Install_Portable_TOP.pdf
    • http://robinzoniya.ru/?p=25621
    • https://promwad.de/sites/default/files/webform/tasks/dg-foto-art-gold-60-full-version-with-keygen-crack-serial.pdf
    • http://www.urbes.be/sites/default/files/webform/applications/iuache634.pdf
    • https://cloudxmedia.com/fl-studio-producer-edition-11-0-1-signature-bundle-patch-mpt-repack-crack/
    • https://facethai.net/upload/files/2022/07/XLELXXqyxc6qtBkHTBo6_07_73329397e47a1161df4f84e8e7950a73_file.pdf
    • https://ex0-sys.app/upload/files/2022/07/NibCO8okCrxtDUKHxe69_07_67bd9f113ae8
    • https://kurditi.com/upload/files/2022/07/69sk1eRCd7BmTw8W2Otx_07_dd13cb4f517
    • https://news.mtkenya.co.ke/advert/mega-man-legacy-collection-crack-download-free-
    • https://alternativeconversation.com/upload/files/2022/07/RnFPdacDLsPIoEpoj4ab_07
    • https://aposhop-online.de/wp-
    • https://promwad.de/sites/default/files/webform/tasks/dg-foto-art-gold-60-full-version-
    • https://cloudxmedia.com/fl-studio-producer-edition-11-0-1-signature-bundle-patch-
    • https://facethai.net/upload/files/2022/07/XLELXXqyxc6qtBkHTBo6_07_73329397e47a
    • https://wmich.edu/system/files/webform/innovative/HD-Online-Player-Singham-2-Hindi-Dubbed-Movie-Downloa.pdf
    • https://wakelet.com/wake/_glOeOjJEW8PliI3-bbTS
    • http://uplefar.yolasite.com/resources/Download-Mastercam-X8-BETTER-Full-Crack-64.pdf
    • http://www.tcpdf.org
    • https://wmich.edu/system/files/webform/innovative/HD-Online-Player-
    • http://uplefar.yolasite.com/resources/Download-Mastercam-X8-BETTER-Full-
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/