Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6a3eabb82adf6ff…

MALICIOUS

PDF

120.4 KB Created: 2022-07-05 01:12:49 +00:00 Authoring application: ranjam (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 55a9475679a86ed041b0424d80cf0ff0 SHA-1: a456997697a615942686962f0c65b190b2aef766 SHA-256: f6a3eabb82adf6ff965de4e04512066da4d338bc538bc08424b3a6c4c063f364
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains multiple links advertising cracked software, a common lure for users seeking pirated applications. The heuristic 'PDF_CRACKED_SOFTWARE_LURE' confirms this, and the embedded URLs provide direct indicators of compromise. The document body was unreadable, limiting further analysis of specific lures.

Machine Learning

  • Nyx PDF Classifier clean score 0.0127

Heuristics 5

  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://blogbasters.com/UGhvdG9zaG9wIDIwMjEgKHZlcnNpb24gMjIpUGh/scalping.appeared?/ZG93bmxvYWR8UHMwY2pOb2ZId3hOalUyT1RneE5UQTBmSHd5TlRjMGZId29UU2tnY21WaFpDMWliRzluSUZ0R1lYTjBJRWRGVGww/cystathione/dollies.fagd PDF link annotation
    • http://meowmeowcraft.com/2022/07/05/adobe-photoshop-2021-version-22-2-activation-free-x64-latest/In PDF document text
    • https://poliestudios.org/campus2022/blog/index.php?entryid=2963In PDF document text
    • http://www.male-blog.com/2022/07/04/photoshop-2020-crack/In PDF document text
    • https://virtual.cecafiedu.com/blog/index.php?entryid=5041In PDF document text
    • https://waoop.com/upload/files/2022/07/fwSUrEUwuwOCBqzYVJyI_05_95cbc7355836022a8aaa0545a8e3d0d1_file.pdfIn PDF document text
    • https://www.airworkgroup.com/system/files/webform/Adobe-Photoshop-CC-2015-version-17.pdfIn PDF document text
    • https://social.deospace.com/upload/files/2022/07/OPOQmaRMpoP2CiRdDT9v_05_95cbc7355836022a8aaa0545a8e3d0d1_file.pdfIn PDF document text
    • http://stroiportal05.ru/advert/adobe-photoshop-2022-version-23-4-1-universal-keygen-3264bit/In PDF document text
    • https://traveljordanagency.com/system/files/webform/Photoshop-2021-Version-223.pdfIn PDF document text
    • https://databasegram.com/2022/07/05/photoshop-2020-version-21-keygen-crack-serial-key-serial-key-pc-windows-march-2022/In PDF document text
    • https://gembeltraveller.com/adobe-photoshop-keygen-only-patch-with-serial-key-download-mac-win/In PDF document text
    • http://khushiyaonline.com/advert/photoshop-2021-version-22-free-download-2022-latest-3/In PDF document text
    • https://wanoengineeringsystems.com/wp-content/uploads/2022/07/Photoshop_CS5_Crack_Keygen___License_Key_WinMac.pdfIn PDF document text
    • https://aqesic.academy/blog/index.php?entryid=6746In PDF document text
    • http://dealskingdom.com/photoshop-2021-install-crack-with-license-code-updated/In PDF document text
    • https://estudandoabiblia.top/wp-content/uploads/2022/07/Adobe_Photoshop_CS6_Torrent_Activation_Code_Free_Download_X64.pdfIn PDF document text
    • https://chatinzone.com/upload/files/2022/07/sWyXchHVe4BkuOZ8e9VY_05_2a83ef6c33afaaea541cbb1996840934_file.pdfIn PDF document text
    • http://kolatia.com/?p=9794In PDF document text
    • https://teenmemorywall.com/adobe-photoshop-cc-2015-version-17-crack-file-only-mac-win-latest/In PDF document text
    • http://jaxskateclub.org/2022/07/05/adobe-photoshop-express-keygenerator-with-key-free/In PDF document text
    • https://plugaki.com/upload/files/2022/07/AHaS6oDmt4PjgpOq35QJ_05_2a83ef6c33afaaea541cbb1996840934_file.pdfIn PDF document text
    • https://www.webkurs.at/blog/index.php?entryid=4582In PDF document text
    • https://2z31.com/photoshop-2022-version-23-0-keygen-for-lifetime-download-for-windows-2022/In PDF document text
    • https://isihomeopatia.com.br/blog/index.php?entryid=3058In PDF document text
    • https://communications.cfaes.ohio-state.edu/system/files/webform/photoshop-2021-version-2231.pdfIn PDF document text
    • http://conchandtan.yolasite.com/resources/Adobe-Photoshop-2021-Version-2201-With-License-Key---WinMac-Updated-2022.pdfIn PDF document text
    • https://sergeykorolyov305.wixsite.com/viecrysunjus/post/adobe-photoshop-2021-version-22-3-free-downloadIn PDF document text
    • https://wakelet.com/wake/JE-GfISJGB2on5i1r7X64In PDF document text
    • https://wakelet.com/wake/ehHJMD9zIJ6oOCUZJgF9ZIn PDF document text
    • https://www.cakeresume.com/portfolios/photoshop-2021-version-22-5-patch-with-serial-keIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text
    • http://conchandtan.yolasite.com/resources/adobe-photoshop-2021-version-2201-with-license-key---winmac-updated-2022.pdfIn PDF document text