Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6bf9fc876429bee…

MALICIOUS

PDF

276.0 KB Created: 2022-07-04 01:00:43 +00:00 Authoring application: warsasj (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 9ae5990b2c7da28ef7b2fe3860462a00 SHA-1: 2add508b456faff27fb27b2840f5471be233af7c SHA-256: f6bf9fc876429bee36405d5ede25d00c2b940453a71b4af38dc865635dccc9f1
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF document contains multiple lures, including advertisements for cracked software and instructions to install remote support tools. The presence of external URIs and specific lures like 'cracked_software_links' and 'SE_REMOTE_SUPPORT_LURE' strongly suggest a malicious intent to trick the user into downloading potentially harmful software or granting unauthorized access. The document's structure and embedded links point towards a phishing or social engineering attack.

Machine Learning

  • Nyx PDF Classifier clean score 0.0044

Heuristics 5

  • Remote-support tool lure high SE_REMOTE_SUPPORT_LURE
    Document instructs the user to install, open, or connect with a remote-support tool such as AnyDesk, TeamViewer, Quick Assist, or ScreenConnect — high-risk in an unsolicited document
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bestentrypoint.com/VmlkZW9Tb2xvIEJELURWRCBSaXBwZXIVml.adkins/poros/ZG93bmxvYWR8U2g3TVcxaWEzeDhNVFkxTmpnNU1qTTFNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA.disempowering.walkthroughs PDF link annotation
    • https://www.plori-sifnos.gr/task-graph-generator-crack-registration-code-pc-windows/In PDF document text
    • https://www.brooklinenh.us/sites/g/files/vyhlif2876/f/file/file/2018_july_-_information_for_residents.pdfIn PDF document text
    • https://lifedreamsorganizer.com/logmein-rescue-crack-for-windows-april-2022/In PDF document text
    • https://superyacht.me/advert/softaken-pdf-locker-crack-free-license-key-download-pc-windows-april-2022/In PDF document text
    • https://triberhub.com/upload/files/2022/07/bEhuRcbscyAPBGVCQA2I_04_83dc913eeaf06b3eb4effe59a56a82d5_file.pdfIn PDF document text
    • http://chat.xumk.cn/upload/files/2022/07/viggcstULv4Pd4A7HXcQ_04_06acc250257d0e49d0641dcbb61c186f_file.pdfIn PDF document text
    • https://firstlineafricajobs.com/wp-content/uploads/2022/07/GDS_Google_Map_WinForms_Control-1.pdfIn PDF document text
    • http://stv.az/?p=13687In PDF document text
    • http://periodistasagroalimentarios.org/advert/mouse-move-logger-crack-free-download-updated-2022/In PDF document text
    • https://xn--80aagyardii6h.xn--p1ai/rule-manager-crack-mac-win/In PDF document text
    • https://promwad.de/sites/default/files/webform/tasks/eircon371.pdfIn PDF document text
    • https://safe-shelf-53131.herokuapp.com/warrkatr.pdfIn PDF document text
    • https://j4miejohnston.com/my-blue-folders-vol-8-crack-for-windows-latest/In PDF document text
    • https://donutsnearby.com/wp-content/uploads/2022/07/Office_to_PDF.pdfIn PDF document text
    • https://newfashionbags.com/water-warner-crack-free-3264bit-march-2022/In PDF document text
    • https://vdsproductions.nl/viki-translator-product-key-full/In PDF document text
    • http://kinectblog.hu/elemental-crack-free-for-pc.htmlIn PDF document text
    • https://smartictbd.com/2022/07/04/flare-crack-torrent-x64-final-2022/In PDF document text
    • https://triberhub.com/upload/files/2022/07/bEhuRcbscyAPBGVCQA2I_04_83dc913eeaf06b3eb4effe59a56a82d5_filIn PDF document text
    • http://chat.xumk.cn/upload/files/2022/07/viggcstULv4Pd4A7HXcQ_04_06acc250257d0e49d0641dcbb61c186f_fileIn PDF document text
    • http://spilevnet.yolasite.com/resources/Night-Lights-Theme-License-Key-Full.pdfIn PDF document text
    • http://alrari.yolasite.com/resources/Free-Opener-2010-Crack-With-Serial-Key.pdfIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text
    • http://alrari.yolasite.com/resources/free-opener-2010-crack-with-serial-key.pdfIn PDF document text