Malicious PDF — malware analysis report

Static analysis result for SHA-256 eab661502d93da84…

MALICIOUS

PDF

136.4 KB Created: 2022-07-08 02:19:47 +00:00 Authoring application: dejasamu (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 435ef558878600815bd58106566eaec0 SHA-1: c75d06f6d4bb4604d1a52331f8165d980250e1be SHA-256: eab661502d93da84e72a12c3b7d11f0660dc8efd68d9f1ee9f94ffc3c4e759b9
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links to other PDF files, a technique often used to inflate search engine rankings and distribute malware. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external PDF link farm, with the primary malicious URL being http://godsearchs.com/... The document body is heavily obfuscated and does not provide clear textual lures, but the presence of numerous links to potentially malicious PDFs strongly suggests a distribution or redirection scheme.

Machine Learning

  • Nyx PDF Classifier clean score 0.0094

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://godsearchs.com/agonizing/arteriole=closer/R3JhdmUgRW5jb3VudGVycyAxMDgwcCBZaWZ5IFN1YnRpdGxlcyAyMgR3J=diarrhoea/leuvensesteenweg.ZG93bmxvYWR8Z2o3WTJ4aWQzeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA
    • https://ideatranslate.ru/fr/system/files/webform/spss-19-serial-key.pdf
    • https://www.tailormade-logistics.com/sites/default/files/webform/tarraw158.pdf
    • https://lyricsandtunes.com/wp-content/uploads/2022/07/prinuldr.pdf
    • https://you.worldcruiseacademy.co.id/upload/files/2022/07/2QBI9sq2swx86vjugVvB_08_eba85880871b97a8a10302bc2968cee5_file.pdf
    • http://hominginportland.com/?p=10765
    • https://training.cybersecurityinstitute.co.za/blog/index.php?entryid=6154
    • https://alessiomastroianni.com/operating-system-by-gary-nutt-free-downloadrar-hot/
    • https://mimaachat.com/upload/files/2022/07/xoJM7yv9GWbSa6XILykY_08_89234a3a1fdc366e7a0e48a45730bbfe_file.pdf
    • https://www.careion.be/sites/default/files/webform/tagtala539.pdf
    • https://www.vsv7.com/upload/files/2022/07/2XIrtQW5IwNorLSdeYPR_08_6c4be5d11b4a071e323d03bfb3be8372_file.pdf
    • http://igpsclub.ru/social/upload/files/2022/07/5GA8hKVaYYJPJUOdswGu_08_eba85880871b97a8a10302bc2968cee5_file.pdf
    • https://shalamonduke.com/wp-content/uploads/2022/07/POSTAL_Redux__Official_Soundtrack_Free_Download_Ativador.pdf
    • https://limeti.com.mx/foro//upload/files/2022/07/B7pCZJ8D893vidkxlmCf_08_89234a3a1fdc366e7a0e48a45730bbfe_file.pdf
    • https://papayu.co/anthony-romeno-feat-jaze-knight-my-home-zippy-top-2/
    • https://waappitalk.com/upload/files/2022/07/Kab5y7H9N1Ds7GYPW6EY_08_eba85880871b97a8a10302bc2968cee5_file.pdf
    • https://levitra-gg.com/?p=19544
    • https://www.amphenolalden.com/system/files/webform/octaharl237.pdf
    • https://you.worldcruiseacademy.co.id/upload/files/2022/07/2QBI9sq2swx86vjugVvB_08_eba8588087
    • https://mimaachat.com/upload/files/2022/07/xoJM7yv9GWbSa6XILykY_08_89234a3a1fdc366e7a0e48
    • https://www.vsv7.com/upload/files/2022/07/2XIrtQW5IwNorLSdeYPR_08_6c4be5d11b4a071e323d03b
    • http://igpsclub.ru/social/upload/files/2022/07/5GA8hKVaYYJPJUOdswGu_08_eba85880871b97a8a1030
    • https://shalamonduke.com/wp-
    • https://limeti.com.mx/foro//upload/files/2022/07/B7pCZJ8D893vidkxlmCf_08_89234a3a1fdc366e7a0e
    • https://waappitalk.com/upload/files/2022/07/Kab5y7H9N1Ds7GYPW6EY_08_eba85880871b97a8a103
    • https://sigs.interserver.net/blocked?ref=aiplgurugram.com/?p=17605
    • https://trello.com/c/pxl49bQi/58-kaakan-marathi-movie-download-dvdrip-201-top
    • https://elprohookeridut.wixsite.com/pupletata/post/advanced-c-programming-by-example-john-w-perry-pdf-15
    • http://www.tcpdf.org
    • https://elprohookeridut.wixsite.com/pupletata/post/advanced-c-programming-by-example-john-w-
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/