Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1c54cda37e63793…

MALICIOUS

PDF

124.8 KB Created: 2022-07-08 05:32:13 +00:00 Authoring application: oskayol (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: ea63a491a0f3b43511768ca7a514cd90 SHA-1: 753376989be1862efb3c857f88cc590353558f4c SHA-256: d1c54cda37e63793957ac50034998cefe8314c345da0dab674c33a6a1b5c28fd
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a significant number of external links, a technique often used for SEO manipulation or to distribute further malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links within a small PDF, suggesting a malicious intent to redirect users. The embedded URL 'http://findinform.com/RWFzZXVzIERhdGEgUmVjb3ZlcnkgTGljZW5zZSBDb2RlRWF/treos.zalaznick/agust.anthromorphic.ZG93bmxvYWR8NkhYYURWaU0zeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA?hypertensionprevention=piney' is a primary indicator of a potential distribution point.

Machine Learning

  • Nyx PDF Classifier clean score 0.0103

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://findinform.com/RWFzZXVzIERhdGEgUmVjb3ZlcnkgTGljZW5jZSBDb2RlRWF/treos.zalaznick/agust.anthromorphic.ZG93bmxvYWR8NkhYYURWaU0zeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA?hypertensionprevention=piney
    • https://www.greatescapesdirect.com/2022/07/circuit-wizard-2-code-activation-hot/
    • https://lfbridge.com/upload/files/2022/07/8NSZbI5aTQdKw4bWRfLH_08_74eb521332f491abd92d489468cd0615_file.pdf
    • https://www.puremeditation.org/2022/07/08/realtek-high-definition-audio-drivers-6-0-8899-1-whql-��-2021/
    • https://www.matera2029.it/wp-content/uploads/2022/07/terrwell.pdf
    • https://young-beach-12760.herokuapp.com/lavamer.pdf
    • https://localdealmonster.com/wp-content/uploads/2022/07/GT100_Driver_20_Crack_NEW.pdf
    • https://mdotm.in/hot-crack-archicad-16-ita/
    • https://simplygroup.it/2022/07/08/kawasaki-bk117-for-xplanetorrent-hit/
    • https://mercatoposto.com/wp-content/uploads/2022/07/talbsast.pdf
    • https://www.mountolivetwpnj.org/sites/g/files/vyhlif4736/f/uploads/brochure_mount_olive_10-22.pdf
    • https://expressionpersonelle.com/tezz-movie-full-portable-download-mp4/
    • http://kireeste.com/?p=43281
    • https://www.amphenolalden.com/system/files/webform/Heat-Distortion-Plugin-Crack.pdf
    • http://tyrannushall.org/?p=11620
    • https://mcguirecapital.com/wp-content/uploads/2022/07/shangene.pdf
    • http://www.theoldgeneralstorehwy27.com/wp-content/uploads/2022/07/Corel_Painter_2019_V1900427_Pre_Fixed_Cracked.pdf
    • https://www.tuttoporte.com/sites/default/files/webform/download-filme-com-merito-dublado.pdf
    • http://www.gurujijunction.com/uncategorized/motdepasselogitracev14/
    • https://peaceful-ravine-11903.herokuapp.com/aleala.pdf
    • https://www.clever-hr.uk/system/files/webform/bartender-775-serial-keygen-dvdrip-branciamore-d.pdf
    • https://lfbridge.com/upload/files/2022/07/8NSZbI5aTQdKw4bWRfLH_08_74eb521332f491abd92d489468cd0615_file
    • http://www.theoldgeneralstorehwy27.com/wp-
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/