Malicious PDF — malware analysis report

Static analysis result for SHA-256 ce0f5cc63d25dc3f…

MALICIOUS

PDF

140.1 KB Created: 2022-07-05 19:34:15 +00:00 Authoring application: yentsher (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: ab94cdb33a14277aef9de4dadcc12140 SHA-1: 5531cfdbb5f4f7fd0501a18c184df322fbdf7656 SHA-256: ce0f5cc63d25dc3f8b3bddb58d5374d2d1b0a70baf5311300ac333213bd9405a
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which are SEO-optimized, suggesting a link farm designed to distribute malicious content. One prominent URL, http://dawnloadonline.com/balco/acheived/apology/RmlmYSAyMgRml?assistantships=/exacted/correspondent/raynay/ZG93bmxvYWR8ajVjTm0xdk1ueDhNVFkxTnpBek5qSXlNM3g4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA, appears to be a direct download link for a payload. The heuristic 'PDF_SEO_LINK_FARM' strongly indicates this malicious intent.

Machine Learning

  • Nyx PDF Classifier clean score 0.0069

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dawnloadonline.com/balco/acheived/apology/RmlmYSAyMgRml?assistantships=/exacted/correspondent/raynay/ZG93bmxvYWR8ajVjTm0xdk1ueDhNVFkxTnpBek5qSXlNM3g4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA
    • https://fessoo.com/upload/files/2022/07/rJW7jNMrv9R68nKFe9Ep_05_1aab10793dd6ec2d3d18c7d9847311d6_file.pdf
    • https://www.beaniescustom.com.au/sites/www.beaniescustom.com.au/files/webform/Fifa-22_47.pdf
    • https://xtc-hair.com/wp-content/uploads/2022/07/Fifa_22-10.pdf
    • http://www.manuperezfoto.com/wp-content/uploads/2022/07/Fifa_22-1.pdf
    • http://www.nextjowl.com/upload/files/2022/07/KQXDovpGkTfqFvgYvSJp_05_cd6d34c6b5aa27b51b0ce7016a77772d_file.pdf
    • http://www.male-blog.com/2022/07/05/fifa-22-nulled-activation-code-with-keygen-macwin/
    • https://nashvilleopportunity.com/fifa-22-patch-full-version-free-download-macwin/
    • https://lll.dlxyjf.com/upload/files/2022/07/MEzH4rneunV9cfwxLYjX_05_973855e92274ac696ccf76809af65a0c_file.pdf
    • https://www.nalabagam.com/fifa-22-key-generator-free-download/
    • http://nelsonescobar.site/?p=3342
    • https://karahvi.fi/wp-content/uploads/2022/07/Fifa_22_Install_Crack__Free_Download_MacWin_2022.pdf
    • https://www.cwwindowcoverings.com.au/sites/default/files/webform/benbree166.pdf
    • https://www.techclipse.com/fifa-22-crack-keygen-with-serial-number-x64/
    • http://elstar.ir/2022/07/06/fifa-22-serial-key-free-registration-code-2022-latest/
    • https://sissycrush.com/upload/files/2022/07/OIlqQhrGfAAvYH7shOWl_05_d10f284aa427a9ee66367d5410ebf613_file.pdf
    • https://maltymart.com/advert/fifa-22-crack-activation-code-free-download-x64-latest/
    • http://www.flexcompany.com.br/flexbook/upload/files/2022/07/4qpaNZUtnoAkJfrRxn9x_05_cd6d34c6b5aa27b51b0ce7016a77772d_file.pdf
    • https://educationnews.co.ke/advert/fifa-22-keygenerator-keygen/
    • https://dzambelis.co.uk/advert/fifa-22-universal-keygen-free/
    • https://kurditi.com/upload/files/2022/07/ecQLvB9MJbSWILQmrHnD_05_cd6d34c6b5aa27b51b0ce7016a77772d_file.pdf
    • https://fessoo.com/upload/files/2022/07/rJW7jNMrv9R68nKFe9Ep_05_1aab10793dd6
    • https://www.beaniescustom.com.au/sites/www.beaniescustom.com.au/files/webform
    • http://www.nextjowl.com/upload/files/2022/07/KQXDovpGkTfqFvgYvSJp_05_cd6d34c
    • http://www.male-blog.com/2022/07/05/fifa-22-nulled-activation-code-with-keygen-
    • https://lll.dlxyjf.com/upload/files/2022/07/MEzH4rneunV9cfwxLYjX_05_973855e9227
    • https://karahvi.fi/wp-
    • https://sissycrush.com/upload/files/2022/07/OIlqQhrGfAAvYH7shOWl_05_d10f284aa
    • https://maltymart.com/advert/fifa-22-crack-activation-code-free-download-
    • http://www.flexcompany.com.br/flexbook/upload/files/2022/07/4qpaNZUtnoAkJfrRxn
    • https://kurditi.com/upload/files/2022/07/ecQLvB9MJbSWILQmrHnD_05_cd6d34c6b5a
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/