PDF static analysis report

Static analysis result for SHA-256 d122e4c134c71de5…

SUSPICIOUS

PDF

138.0 KB Created: 2022-07-07 23:08:14 +00:00 Authoring application: bethan (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 29d37ec22d38d264000b2cc62f475630 SHA-1: b15412ad8fb563dc3b075671fbd6c8cbf6092e00 SHA-256: d122e4c134c71de5945dbc81067c7d327e831c450521da2811067e233c2ecda3
44 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF document contains a heuristic firing for a password-protected archive lure, indicating an attempt to trick the user into decrypting malicious content. An external URI pointing to 'blogbasters.com' was extracted, which likely serves as the download location for the malicious archive. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier clean score 0.0077

Heuristics 3

  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://blogbasters.com/argonaunts.ZG93bmxvYWR8N2R4TjI1bWFYeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.diem/marriagematters/salamey/dalton/WnluZ2EgUG9rZXIgSGFjayBWNzM1IFBhc3N3b3JkcmFyYWRkcwWnl PDF link annotation
    • https://arcmaxarchitect.com/sites/default/files/webform/parallels-plesk-panel-11-full-crack.pdfIn PDF document text
    • https://www.iltossicoindipendente.it/2022/07/07/hd-online-player-kelly-huizen-video-download-hot/In PDF document text
    • https://gameurnews.fr/upload/files/2022/07/TljOYlCUrS6PerCBNa17_07_d5cd906046b0d779e7f6550c167e02f3_file.pdfIn PDF document text
    • https://medcoi.com/network/upload/files/2022/07/vH5BlxR8zLnyUswKErwb_07_b8ef9b4c3553a0d0810f762d5e4e9e61_file.pdfIn PDF document text
    • https://www.kb-recruitment.co.uk/system/files/webform/cv/Warcraft-III-Reign-Of-Chaos-The-Frozen-Throne-127B-Cheat-Engine.pdfIn PDF document text
    • http://streamcolors.com/?p=20511In PDF document text
    • https://friendship.money/upload/files/2022/07/SAh9npqwIy8dBqd48Q6n_07_d5cd906046b0d779e7f6550c167e02f3_file.pdfIn PDF document text
    • https://amoserfotografo.com/advert/mw2phbte-rar/In PDF document text
    • https://mandarinrecruitment.com/system/files/webform/ausarie753.pdfIn PDF document text
    • http://asopalace.com/?p=6004In PDF document text
    • https://www.flordechanar.cl/wp-content/uploads/2022/07/ENB_Series_FSX_Ultra_Realisticexe.pdfIn PDF document text
    • https://afroworld.tv/upload/files/2022/07/oj8QwD637s4B2OntnEhy_07_d5cd906046b0d779e7f6550c167e02f3_file.pdfIn PDF document text
    • https://versiis.com/44663/adeko-9-mutfak-full-ndir-indir-torrent-torrent-upd/In PDF document text
    • https://www.cameraitacina.com/en/system/files/webform/feedback/the-veer-zaara-full-movie-in-hindi-hd-1080p-download.pdfIn PDF document text
    • https://www.reperiohumancapital.com/system/files/webform/Bienvenue-Chez-les-Rozes-avi.pdfIn PDF document text
    • https://xcconcepts.com/wp-content/uploads/2022/07/Risale_I_Kudsiyye_Tercumesi_Mahmut_Ustaosmanoglu_49_2021.pdfIn PDF document text
    • https://wakelet.com/wake/rBWINcap7B1RcHa6ofZ2FIn PDF document text
    • https://trello.com/c/eDCTNLnf/146-mastizaade-hindi-movie-free-full-download-3gp-mp4In PDF document text
    • https://www.lakeheadu.ca/system/files/webform/employment_opportunities/nerlaw451.pdfIn PDF document text
    • https://wakelet.com/wake/tkjoCNNR8rkUgLgFosLGQIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text