Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee2d83319a1595c9…

MALICIOUS

PDF

123.6 KB Created: 2022-07-04 09:12:51 +00:00 Authoring application: randlat (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 0da9b5ebc4d00ec105aa8565c3594450 SHA-1: 67248d337d9a45a99cafa8855e8850fa7d581617 SHA-256: ee2d83319a1595c99822babeca31b3e7dbb29d10030d465e3da03a01b47b39f0
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links, indicating a link farm or redirection mechanism. The primary heuristic identified an external URI pointing to 'bestentrypoint.com', which is likely a distribution point for malicious content. The PDF structure and extensive linking suggest an attempt to drive traffic to potentially harmful websites.

Machine Learning

  • Nyx PDF Classifier clean score 0.0076

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bestentrypoint.com/pinarello/accute.SW5zdGFsbFNoaWVsZCAtIFByZW1pZXIgRWRpdGlvbgSW5&azwbyageacaboagkaywl.emptied.ZG93bmxvYWR8VEczWkdjNWNYeDhNVFkxTmpnNU1qTTFNbng4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk.kellyrowlandringtones.retail
    • https://www.probnation.com/upload/files/2022/07/MRJE1dpCU7eSgc8X7yOY_04_36027a78a192748445f9b949eafa7784_file.pdf
    • https://abckidsclub.pl/wp-content/uploads/2022/07/System_Information_And_Comparison_Crack__For_PC_Updated2022.pdf
    • http://sturgeonlakedev.ca/2022/07/04/dvd-x-utilities-2021-free-download/
    • https://rakyatmaluku.id/upload/files/2022/07/ZQ8veTfHioUuFo9Qp6fo_04_36027a78a192748445f9b949eafa7784_file.pdf
    • https://swisshtechnologies.com/batch-access-database-compactor-4-2-66-crack-with-license-key-x64-april-2022-2/
    • https://gamersmotion.com/wandering-spider-screensaver-crack-lifetime-activation-code-free-for-pc/
    • https://bodhirajabs.com/wp-content/uploads/2022/07/ralsoly.pdf
    • https://mevoydecasa.es/globe-crack-free-download/
    • https://lifedreamsorganizer.com/veecool-video-capture-license-code/
    • https://lll.dlxyjf.com/upload/files/2022/07/MUOWbM1vru91mM5Wwh7I_04_36027a78a192748445f9b949eafa7784_file.pdf
    • https://farmaciacortesi.it/proteomexchange-submission-tool-crack-download/
    • https://www.merexpression.com/upload/files/2022/07/GBhhdUrgJcVpSK2AOfWR_04_42a4f5c61633b279e8822e7efeb7b615_file.pdf
    • https://homeimproveinc.com/ftp-uploader-with-keygen-latest/
    • https://go.roguecc.edu/sites/go.roguecc.edu/files/webform/Sony-Ericsson-Ringtone-Convertor.pdf
    • https://topnotchjobboard.com/system/files/webform/resume/access-remote-pc.pdf
    • https://sheltered-inlet-78551.herokuapp.com/reffor.pdf
    • http://dottoriitaliani.it/ultime-notizie/senza-categoria/metal-dectector-database-activation/
    • http://scamfie.com/?p=26355
    • https://africanscientists.africa/wp-content/uploads/2022/07/VolcanoCam.pdf
    • https://www.myoccu.org/system/files/webform/community-recruit-volunteers/PCCLEANER.pdf
    • https://www.probnation.com/upload/files/2022/07/MRJE1dpCU7eSgc8X7yOY_04_36027a78a192
    • https://abckidsclub.pl/wp-content/uploads/2022/07/System_Information_And_Comparison_Crack
    • https://rakyatmaluku.id/upload/files/2022/07/ZQ8veTfHioUuFo9Qp6fo_04_36027a78a19274844
    • https://swisshtechnologies.com/batch-access-database-compactor-4-2-66-crack-with-license-
    • https://gamersmotion.com/wandering-spider-screensaver-crack-lifetime-activation-code-free-
    • https://lll.dlxyjf.com/upload/files/2022/07/MUOWbM1vru91mM5Wwh7I_04_36027a78a19274844
    • https://www.merexpression.com/upload/files/2022/07/GBhhdUrgJcVpSK2AOfWR_04_42a4f5c616
    • https://go.roguecc.edu/sites/go.roguecc.edu/files/webform/Sony-Ericsson-Ringtone-
    • http://www.tcpdf.org
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/