Malicious PDF — malware analysis report

Static analysis result for SHA-256 d3be35830178c56e…

MALICIOUS

PDF

119.5 KB Created: 2022-07-08 01:53:13 +00:00 Authoring application: vendnaf (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: d02e12aae9db8f625030278c60443de0 SHA-1: 619377194c9986c132134fa5fafa4b9cbb0dfffa SHA-256: d3be35830178c56eeb3b89fd3519c6d18b8a4dc2bf8077242756c51a6e1a1396
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a heuristic firing for a URI pointing to a suspicious domain, likely intended to host malicious content or redirect the user. Additionally, a PDF link farm heuristic indicates the document is designed to host numerous external links, a common tactic for SEO poisoning or distributing malware. The presence of these elements suggests the document's primary purpose is to facilitate malicious activity through external resources.

Machine Learning

  • Nyx PDF Classifier clean score 0.0270

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rocketcarrental.com/hydrocodone/magnanimous/metabolically/ZG93bmxvYWR8TDVQWW5nMGNYeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/?seidelman&pasteurized=U2ltQ2l0eSBVcGRhdGUuMTAuMSAxNyBETEMuUmVwYWNrLVIuRy5NZWNoYW5pY3MgU2VyaWFsIEtleSBLZXlnZW4U2l=misers
    • https://www.townofwinchendon.com/sites/g/files/vyhlif8401/f/uploads/fy2015values.pdf
    • https://slab-bit.com/terjemahan-kitab-minhajul-muslim-pdf-68-better/
    • http://sharedsuccessglobal.com/marketplace/upload/files/2022/07/xelTKzGo6g3Zz5qfUGl6_08_c43f47b4072e752f10dc4914c9a69629_file.pdf
    • https://akastars.com/upload/files/2022/07/5QRea4wsJqhv8pGPj2Pi_08_008b31ba26b145e0ea4bf3d4efb023d4_file.pdf
    • https://promwad.de/sites/default/files/webform/tasks/i-croods-3d-2013-divx-ita-torrent.pdf
    • https://maltymart.com/advert/mission-kashmir-hindi-720p-download-portable/
    • https://www.townofnewbury.org/sites/g/files/vyhlif951/f/news/official_ate_results_5.10.2022.pdf
    • https://rei4dummies.com/grand-theft-auto-v-gta-5-full-pc-iso-key-generator-top/
    • https://blackhawkfasteners.com.au/wp-content/uploads/2022/07/Panzer_Elite_Action_Fields_Of_Glory_Download_Full_Version.pdf
    • https://thoitranghalo.com/2022/07/08/8211759-9137094-gt-e2250-flash-loader-7-5-4-csc-v0-4-lite-epub-free/
    • https://www.amphenolalden.com/system/files/webform/diarglo677.pdf
    • https://social.quilt.idv.tw/upload/files/2022/07/SxmaZDc1JhZzNEEUpXO2_08_44851fb778c1bebfd720c8703ca48b7c_file.pdf
    • https://wethesalesengineers.com/wp-content/uploads/2022/07/Windows_Xp_Tablet_Edition_2005iso_FREE.pdf
    • https://motofamily.com/ebook-free-download-gateways-to-art-top/
    • https://www.cab-bc.org/system/files/webform/vicky-donor-in-hindi-movie-download.pdf
    • https://esmuseum.com/wp-content/uploads/2022/07/autocom_2122_keygen.pdf
    • https://greenearthcannaceuticals.com/halo-license-key-best/
    • https://www.chemfreecarpetcleaning.com/wp-content/uploads/2022/07/Windows_78110_x86x64_AIO_70in1_adguard_free_download.pdf
    • https://shoplidaire.fr/wp-content/uploads/2022/07/ArcsoftTotalMedia35Serialw_DriversKworld330340115315_LINK_Download_Pc.pdf
    • http://sharedsuccessglobal.com/marketplace/upload/files/2022/07/xelTKzGo6g3Zz5qfUGl6_08_c43f47b4072e752f10dc
    • https://blackhawkfasteners.com.au/wp-
    • https://social.quilt.idv.tw/upload/files/2022/07/SxmaZDc1JhZzNEEUpXO2_08_44851fb778c1bebfd720c8703ca48b7c_fil
    • https://www.chemfreecarpetcleaning.com/wp-
    • https://shoplidaire.fr/wp-
    • https://liberalarts.tulane.edu/es/system/files/webform/mari/be-awesome-live-awesome-by-himesh-pdf-download.pdf
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/