Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1860955fab12ac5…

MALICIOUS

PDF

126.2 KB Created: 2022-07-04 00:56:34 +00:00 Authoring application: anaqua (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 89089ffa0bf1736e88e372e24d900f30 SHA-1: 30b1b2aa9b79d87f5fdb27f151ad17fb6831e079 SHA-256: e1860955fab12ac52fa9910b2ad78c02c553bd853f49b837375c745d93964c80
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, with a critical heuristic firing for a 'PDF_SEO_LINK_FARM'. One of the primary external links points to 'http://emailgoal.com/', which is likely intended to host or redirect to a malicious payload. The document body is heavily obfuscated and does not provide direct clues to its intent beyond the presence of these links.

Machine Learning

  • Nyx PDF Classifier clean score 0.0106

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://emailgoal.com/cuts/ZG93bmxvYWR8VGg0TVdoc2JueDhNVFkxTmpnNU1qTTFNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/mazzilli/QmFja2dyb3VuZCBFcmFzZXIQmF.suburban?asenski=
    • http://theinspirationseekers.com/portable-treedbnotes-pro-1-0-0-197-crack-final-2022/
    • https://mandarininfo.com/rpitch-crack-torrent-free-download/
    • https://dhakahalalfood-otaku.com/oven-fresh-mailto-link-wizard-2015-06-30-1925-crack-x64-latest/
    • https://delicatica.ru/wp-content/uploads/2022/07/Aiseesoft_PDF_to_Excel_Converter.pdf
    • https://vipfitnessproducts.com/projectdivx-x64-april-2022/
    • https://shielded-reaches-86473.herokuapp.com/zethvla.pdf
    • https://my.rbwm.gov.uk/system/files/webform/24250/1656896190/192.154.253.70/pranava760.pdf
    • https://vegbyte.com/wp-content/uploads/2022/07/Imagus_For_Chrome__Crack_Latest.pdf
    • https://homeoenergy.com/wp-content/uploads/2022/07/Photo_Box_Pro__For_PC.pdf
    • http://thetruckerbook.com/2022/07/04/ashampoo-media-sync-incl-product-key-download-for-windows-final-2022/
    • https://todaysmodernhomes.com/wp-content/uploads/2022/07/Amazing_Portal_Generator.pdf
    • http://bookmanufacturers.org/abc-kid-genius-with-keygen-3264bit-updated-2022
    • https://sut.oribentech.com/advert/boost-crack-registration-code-for-pc-2022-new/
    • http://lms.courses4u.in/blog/index.php?entryid=8158
    • https://robertasabbatini.com/qdict-patch-with-serial-key-x64-april-2022/
    • https://drogueriaconfia.com/rapla-crack-free-download-pc-windows/
    • http://babauonline.com/edge-password-manager-activation-code-free-for-pc-2022-latest/
    • https://onlineshopmy.com/wp-content/uploads/2022/07/zopdor.pdf
    • http://theinspirationseekers.com/portable-treedbnotes-
    • https://dhakahalalfood-otaku.com/oven-fresh-mailto-link-
    • https://delicatica.ru/wp-
    • https://my.rbwm.gov.uk/system/files/webform/24250/1656896190/192
    • https://vegbyte.com/wp-
    • https://homeoenergy.com/wp-
    • http://thetruckerbook.com/2022/07/04/ashampoo-media-sync-incl-
    • https://todaysmodernhomes.com/wp-
    • http://bookmanufacturers.org/abc-kid-genius-with-keygen-3264bit-
    • https://sut.oribentech.com/advert/boost-crack-registration-code-for-
    • https://robertasabbatini.com/qdict-patch-with-serial-key-
    • http://babauonline.com/edge-password-manager-activation-code-free-
    • https://honors.oregonstate.edu/sites/honors.oregonstate.edu/files/strategic_plan_2020-2025.pdf
    • https://networny-social.s3.amazonaws.com/upload/files/2022/07/ozm2vxIpelFkKAml21Uq_04_5af080f79eb53d3e0dd3a735bb2e18b2_file.pdf
    • http://www.tcpdf.org
    • https://honors.oregonstate.edu/sites/honors.oregonstate.edu/files/strat
    • https://networny-social.s3.amazonaws.com/upload/files/2022/07/ozm2
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/