Malicious PDF — malware analysis report

Static analysis result for SHA-256 f8069f0ce344374a…

MALICIOUS

PDF

139.2 KB Created: 2022-07-05 16:52:09 +00:00 Authoring application: vasene (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 8a5839dcf5ad373ede0f1882294a7210 SHA-1: 5c1aeef434d73b19b37a5fac3d1edab77bda362e SHA-256: f8069f0ce344374ab730b1cce6bc3422dfc05ec17640f12be44b6b0f7a9dea55
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, a technique often used to distribute malware or phish for credentials. One of the embedded URLs, http://find24hs.com/dosha/buonanoce/feedmyipods/fruit/ZG93bmxvYWR8aGg5TVhVeGRueDhNVFkxTnpBek5qSXlNM3g4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/tatties/harmonycoaching.nicad?RmlmYSAyMgRml=, is flagged as malicious. The document body is heavily obfuscated and does not provide clear user-facing content, further suggesting a malicious intent behind the link farm.

Machine Learning

  • Nyx PDF Classifier clean score 0.0045

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://find24hs.com/dosha/buonanoce/feedmyipods/fruit/ZG93bmxvYWR8aGg5TVhVeGRueDhNVFkxTnpBek5qSXlNM3g4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/tatties/harmonycoaching.nicad?RmlmYSAyMgRml=
    • https://www.sunsquare.com/system/files/webform/useruploads/fifa-22_27.pdf
    • https://www.oakland-nj.org/sites/g/files/vyhlif1026/f/uploads/borough_calendar_2022.pdf
    • https://fajas.club/2022/07/05/fifa-22-mac-win-2/
    • https://beautyprosnearme.com/fifa-22-crack-patch-x64/
    • https://comoemagrecerrapidoebem.com/?p=23471
    • https://1w74.com/fifa-22-crack-exe-file-free-download-mac-win-2022/
    • https://poetbook.com/upload/files/2022/07/M3HyER6b1UBng4v5Ryz1_05_94b78d48ae2ae8bffbb8f1d33d684724_file.pdf
    • https://fpp-checkout.net/wp-content/uploads/2022/07/aleeisa.pdf
    • https://mykingdomtoken.com/upload/files/2022/07/e34aKgvKQUuyrQoVFMIY_05_94b78d48ae2ae8bffbb8f1d33d684724_file.pdf
    • https://ictlife.vn/upload/files/2022/07/HxJMtquEKvaItDkCmFzc_05_c73db3cef1415170211b5fb97ba6a183_file.pdf
    • http://staffdirect.info/wp-content/uploads/2022/07/Fifa_22_Activation___Product_Key_Full_MacWin_March2022.pdf
    • https://geto.space/upload/files/2022/07/7ha4xzlMjaD7YYCKYfXR_05_94b78d48ae2ae8bffbb8f1d33d684724_file.pdf
    • http://increate.net/fifa-22-with-license-key-product-key-full-download/
    • https://www.eclateng.com/sites/default/files/webform/Fifa-22.pdf
    • https://swapandsell.net/2022/07/05/fifa-22-nulled-with-full-keygen-free-download-for-pc-latest/
    • https://parleafrique.com/wp-content/uploads/2022/07/choalo.pdf
    • https://affiliateschools.com/upload/files/2022/07/KhyZPYZH85orWj2VLKBp_05_c73db3cef1415170211b5fb97ba6a183_file.pdf
    • https://poetbook.com/upload/files/2022/07/M3HyER6b1UBng4v5Ryz1_05_94b78d48ae2ae8bffbb8f1d
    • https://mykingdomtoken.com/upload/files/2022/07/e34aKgvKQUuyrQoVFMIY_05_94b78d48ae2ae8bff
    • https://ictlife.vn/upload/files/2022/07/HxJMtquEKvaItDkCmFzc_05_c73db3cef1415170211b5fb97ba6a
    • http://staffdirect.info/wp-
    • https://geto.space/upload/files/2022/07/7ha4xzlMjaD7YYCKYfXR_05_94b78d48ae2ae8bffbb8f1d33d6
    • https://affiliateschools.com/upload/files/2022/07/KhyZPYZH85orWj2VLKBp_05_c73db3cef1415170211
    • https://www.bsc.es/system/files/webform/cv_employment/mygegen638.pdf
    • https://brd.gov.md/sites/default/files/webform/attachments/vannail481.pdf
    • https://socialstudentb.s3.amazonaws.com/upload/files/2022/07/VXTiiUV9mUdw1b5dO9JY_05_94b78d48ae2ae8bffbb8f1d33d684724_file.pdf
    • http://www.tcpdf.org
    • https://socialstudentb.s3.amazonaws.com/upload/files/2022/07/VXTiiUV9mUdw1b5dO9JY_05_94b78d
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/