Malicious PDF — malware analysis report

Static analysis result for SHA-256 d36f9f59e7489536…

MALICIOUS

PDF

119.8 KB Created: 2022-07-05 07:46:15 +00:00 Authoring application: lensha (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: f14d8690909d01594d2074757c364380 SHA-1: aab4d33f06c6ce35a89e80832ad3925f0c2ab201 SHA-256: d36f9f59e748953640924038ee6389dbdd2b84ad4a1eb7bb127cb4cab9104652
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. One of the primary external links, http://rocketcarrental.com/awstats.marmot/corporate/QWRvYmUgUGhvdG9zaG9wIENDIDIwMTQQWR/roadmate/shellee/tainos?ZG93bmxvYWR8OEtOT1doaWQzeDhNVFkxTmprNE1UVXdOSHg4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk=, is flagged as suspicious. The document body is heavily obfuscated and does not provide clear textual content, but the presence of numerous links, many pointing to PDF files with software-related names, suggests a lure for downloading potentially unwanted or malicious software.

Machine Learning

  • Nyx PDF Classifier clean score 0.0137

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rocketcarrental.com/awstats.marmot/corporate/QWRvYmUgUGhvdG9zaG9wIENDIDIwMTQQWR/roadmate/shellee/tainos?ZG93bmxvYWR8OEtOT1doaWQzeDhNVFkxTmprNE1UVXdOSHg4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk=
    • https://gf-tunenoe.dk/wp-content/uploads/2022/07/Photoshop_CC_2015_Version_16_For_Windows_April2022.pdf
    • https://blooming-plains-83292.herokuapp.com/wendkap.pdf
    • https://pure-sierra-15197.herokuapp.com/osirash.pdf
    • https://guarded-caverns-85868.herokuapp.com/Photoshop_2021_Version_225.pdf
    • https://murmuring-peak-49398.herokuapp.com/claucher.pdf
    • https://ipa-softwareentwicklung.de/wp-content/uploads/2022/07/Photoshop_CS5_universal_keygen__Product_Key.pdf
    • https://vincyaviation.com/wp-content/uploads/2022/07/Adobe_Photoshop_2020_version_21_Keygen_Crack_Serial_Key___Product_Key_Download_2022_New.pdf
    • https://coi-csod.org/wp-content/uploads/2022/07/Photoshop_2021_Version_2211.pdf
    • https://plainbusiness.net/wp-content/uploads/2022/07/Photoshop_2021_Version_224.pdf
    • https://mevoydecasa.es/wp-content/uploads/2022/07/Adobe_Photoshop_2021_Version_2242_full_license__Free.pdf
    • https://seoburgos.com/wp-content/uploads/2022/07/yuspalm.pdf
    • https://young-bastion-19712.herokuapp.com/Photoshop_2022_version_23.pdf
    • https://solaceforwomen.com/wp-content/uploads/2022/07/Adobe_Photoshop_CC_2015_version_17-1.pdf
    • https://hirupmotekar.com/wp-content/uploads/Photoshop_2021_Version_223_Updated.pdf
    • https://nameme.ie/wp-content/uploads/2022/07/ioldav.pdf
    • https://immense-tor-69704.herokuapp.com/Adobe_Photoshop_2022_Version_2301.pdf
    • http://www.visitfayette.com/wp-content/uploads/elilook.pdf
    • https://captainseduction.fr/wp-content/uploads/2022/07/javell.pdf
    • https://www.folusci.it/wp-content/uploads/2022/07/shalau.pdf
    • https://thoitranghalo.com/wp-content/uploads/2022/07/brolark.pdf
    • https://serene-hollows-30103.herokuapp.com/Photoshop_2021.pdf
    • https://kalibatacitymurah.com/wp-content/uploads/2022/07/Adobe_Photoshop_CC_2018_Version_19_keygen_only__With_Full_Keygen_3264bit.pdf
    • https://ibipti.com/wp-content/uploads/2022/07/Adobe_Photoshop_2021_Version_223_Hacked__Free_April2022.pdf
    • https://wakelet.com/wake/LTSZZNp7ACeS-8ZdXeiH1
    • http://posscrapcon.yolasite.com/resources/Photoshop-2021-KeyGenerator--With-Key-Free-For-PC-March2022.pdf
    • https://trello.com/c/pofxIIBH/79-adobe-photoshop-2021-version-2231-crack-full-version-free-updated-2022
    • https://isroifiscaimit.wixsite.com/danchoedaba/post/adobe-photoshop-2022-version-23-0-2-keygen-generator-free-download
    • https://trello.com/c/e3fZMMoP/89-adobe-photoshop-2022-version-23-crack-full-version-license-key-mac-win-updated
    • http://consbelsre.yolasite.com/resources/Photoshop-CC-2014-Hack-Patch--With-Product-Key-Free-For-PC-Final-2022.pdf
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/