Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1e73d49dbe5bcf9…

MALICIOUS

PDF

142.7 KB Created: 2022-07-01 04:39:58 +02:00 Authoring application: leachr (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: ed51d85d2ee69ffb6e1d0ee8e4443830 SHA-1: 7b1fec6fc5ff80c97a488c5588b337ee4787abfe SHA-256: d1e73d49dbe5bcf90bcfdf47501759f78724fda4b3c5d5b67e92f0f291449216
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or SEO spamming tactic. One prominent URL, http://sitesworlds.com/ZG93bmxvYWR8MTF5YW5wbGZId3hOalUyTmpRd09ERTNmSHd5TlRjMGZId29UU2tnY21WaFpDMWliRzluSUZ0R1lYTjBJRWRGVGww/tacked/celeron/conceptions.nonexistent.YWRvYmUgcGhvdG9zaG9wIGZyZWUgZG93bmxvYWQgZm9yIHdpbmRvd3MgNyBsaWZldGltZQYWR/?overclocked=giancarlo, appears to be a lure for downloading software. The document body was not sufficiently readable to provide further context.

Machine Learning

  • Nyx PDF Classifier clean score 0.0077

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sitesworlds.com/ZG93bmxvYWR8MTF5YW5wbGZId3hOalUyTmpRd09ERTNmSHd5TlRjMGZId29UU2tnY21WaFpDMWliRzluSUZ0R1lYTjBJRWRGVGww/tacked/celeron/conceptions.nonexistent.YWRvYmUgcGhvdG9zaG9wIGZyZWUgZG93bmxvYWQgZm9yIHdpbmRvd3MgNyBsaWZldGltZQYWR/?overclocked=giancarlo
    • https://www.neteduproject.org/wp-content/uploads/photoshop_apk_free_download_for_pc.pdf
    • https://athome.brightkidspreschool.com/blog/index.php?entryid=2498
    • http://www.cromwellct.com/sites/g/files/vyhlif2976/f/uploads/20160930142853642.pdf
    • http://dichvuhoicuoi.com/wp-content/uploads/2022/07/shazim_background_remove_photoshop_actions_download.pdf
    • https://otelgazetesi.com/advert/how-to-install-adobe-photoshop-cs4-on-windows-xp/
    • https://www.velocitynews.co.nz/advert/photoshop-cs3-license-key/
    • http://igsarchive.org/wp-content/uploads/2022/06/Photoshop_73_Torrent_WinMac.pdf
    • https://virtudojo.com/wp-content/uploads/2022/06/deutmagn.pdf
    • https://eladhatatlan.hu/advert/free-photoshop-tutorials-at-indesignsecrets/
    • http://www.360sport.it/advert/download-adobe-photoshop-elements-8/
    • http://vogelmorntennisclub.com/its-an-old-trick-of-science-to-say-something-is-true-in-principle/
    • https://www.be-the-first.it/wp-content/uploads/2022/07/Download_Mockup_Logo_Photoshop.pdf
    • https://movingservices.us/index.php/2022/07/01/download-photo-editor-cracke/
    • https://www.promorapid.com/upload/files/2022/07/imdiIFee1eFuI5XaMGJQ_01_43fe94d0f61297698ced2335c09dc4c7_file.pdf
    • https://www.cameraitacina.com/en/system/files/webform/feedback/download-edit-gambar-photoshop.pdf
    • https://akastars.com/upload/files/2022/07/3LkTzZZLcdWPDOwtGoGy_01_43fe94d0f61297698ced2335c09dc4c7_file.pdf
    • https://arabwomeninfilms.media/wp-content/uploads/2022/07/Adobe_Photoshop_CC_2020_Free_Download.pdf
    • http://cuisinefavorits.online/?p=7893
    • https://mandarinrecruitment.com/system/files/webform/adobe-photoshop-fix-download-apkpure.pdf
    • https://www.sanjeevsrivastwa.com/photoshop-cs5-would-require-photoshop-cs5-free/
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000028d0.bin
56464b80a5ce6793253e3b1cd31b13eeb1e98b153a67d576463da0ccb6490a82
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x28D0 120252 bytes
stream_010_off0001ca75.bin
df221e87b81d1531cafdadb6c09a602e9f604d1baf0a17bbd350cbb83baa06f7
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1CA75 119072 bytes