Malicious PDF — malware analysis report

Static analysis result for SHA-256 018ff17786084148…

MALICIOUS

PDF

135.8 KB Created: 2022-09-09 14:31:44 +00:00 Authoring application: ultibark (via PDF Master 1.0.1) First seen: 2026-04-08
MD5: 1aedbdcfd517cd7455d6421ba4039f3b SHA-1: c6214eaff8946cff6c263c7ddb3ce9307a748702 SHA-256: 018ff177860841485e0c6ed3da75e1083f1261ad4f2606ef36f52df6c1318d62
264 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document functions as a link farm, primarily advertising cracked software and providing direct links to download doorways. The document body and heuristics indicate a clear intent to lure users to download potentially malicious software disguised as cracked applications. The presence of multiple URLs pointing to download gateways and cracked software lures strongly suggests a phishing or malware distribution campaign.

Machine Learning

  • Nyx PDF Classifier clean score 0.0006

Heuristics 8

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Cracked-software lure uses shortlink/download gateway critical PDF_CRACKED_SOFTWARE_SHORTLINK_LURE
    PDF visible text advertises a crack, serial number, archive, or pirated-software download and pairs it with a shortlink or encoded download gateway. This is a high-confidence social-engineering carrier for unwanted software or droppers; the PDF itself is not a parser exploit.
  • Cracked-software lure uses download-gateway redirectors high PDF_CRACKED_SOFTWARE_REDIRECTOR_LINK_FARM
    PDF contains multiple cracked-software/keygen/serial-key lure links together with long encoded download-gateway URLs or known crack-download redirector hosts. This is stronger than generic piracy vocabulary: the document is an SEO lure that funnels users through redirect/download infrastructure commonly used for adware, unwanted software, or droppers.
  • PDF links to a cracked-software download doorway (base64-obfuscated) high PDF_CRACKED_SOFTWARE_DOWNLOAD_DOORWAY
    PDF's embedded link hides a pirated-software title as a base64 blob inside the URL path/query (and/or carries the ``download|`` doorway-template marker), rather than in visible text. This is a TCPDF-generated SEO doorway that ranks for software-piracy searches and funnels users to fake 'crack/keygen' download pages distributing adware, potentially-unwanted programs, or droppers. The base64 encoding is deliberate obfuscation to evade plaintext lure rules; the PDF itself carries no parser exploit — the risk is the linked crack-download destination.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://starsearchtool.com/aswan/?ambleve/ZG93bmxvYWR8WW85T1Rnd2VIeDhNVFkyTWpZNE1ETTVNSHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA=cornbread/RlVMTCBNYWdpY0lTTyB2NS41IEJ1aWxkIDI1OSBQb3J0YWJsZQRlV.anyhow PDF link annotation
    • https://furrymonde.com/wp-content/uploads/2022/09/vittfana.pdfIn PDF document text
    • https://ikcasino.com/2022/09/09/ecs-h61h2-mv-driver-2/In PDF document text
    • http://www.chelancove.com/wp-content/uploads/2022/09/taipgody.pdfIn PDF document text
    • https://ayusya.in/wp-content/uploads/Horoscope_Explorer_Pro_V__381_64_Bit_TOP.pdfIn PDF document text
    • http://eyescreamofficial.com/?p=3157In PDF document text
    • https://l1.intimlobnja.ru/driver-talent-pro-6-crack-patch-plus-serial-key-free-download-verified/In PDF document text
    • https://www.ocacp.com/wp-content/uploads/2022/09/halkaf.pdfIn PDF document text
    • http://asopalace.com/?p=17900In PDF document text
    • https://cooltto.com/wp-content/uploads/Spektroskopia_Laserowa_Demtroder_Pdf_Download_UPD.pdfIn PDF document text
    • https://www.spaziodentale.it/wp-content/uploads/2022/09/Direct_X_11_FULLOfflineAryaN_L33TLittleFairyRG_Serial_Key_ke-1.pdfIn PDF document text
    • https://lannews.net/advert/xara-3d-maker-v7-0-0-415-free-crack-set/In PDF document text
    • https://ventanasantiruido.info/2022/09/09/altium-designer-13-torrent-5/In PDF document text
    • https://en-media.tv/advert/flash-cs6-portable/In PDF document text
    • http://mein-portfolio.net/wp-content/uploads/2022/09/Brian_Lara_International_Cricket_2007_Pc_Crack_FREE_Only.pdfIn PDF document text
    • https://pi-brands.com/wp-content/uploads/2022/09/kenrily.pdfIn PDF document text
    • http://www.chandabags.com/rohs-hd-5450-driver-download-verifiedtrmds/In PDF document text
    • https://cadorix.ro/wp-content/uploads/2022/09/oddiambr-1.pdfIn PDF document text
    • https://ninja-hub.com/ufed-physical-analyzer-download-full-crack-idm/In PDF document text
    • https://manglarbymoms.co/wp-content/uploads/2022/09/Artcam_PRO_81_Acqdll.pdfIn PDF document text
    • http://rootwordsmusic.com/wp-content/uploads/2022/09/sage_act_premium_2013_keygen.pdfIn PDF document text
    • https://www.spaziodentale.it/wp-In PDF document text
    • http://mein-portfolio.net/wp-In PDF document text
    • http://starsearchtool.com/aswan/?ambleve/zg93bmxvywr8ww85t1rnd2viedhnvfkytwpzne1ettvnshg4twpvnu1iedhlrtbwsuzkdmntundjbvz6y3lcyldfmu1vbejesuzzeulgqkvsbda=cornbread/rlvmtcbnywdpy0lttyb2ns41iej1awxkidi1osbqb3j0ywjszqrlv.anyhowIn PDF document text
    • http://mein-portfolio.net/wp-content/uploads/2022/09/brian_lara_international_cricket_2007_pc_crack_free_only.pdfIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002959.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2959 84508 bytes
SHA-256: 2b7ba551bea82cc3307397981c1dbeb1b78486f95f2eb14e5e58d4e1b24edb0c
font_01_sfnt_off0000b145.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB145 83036 bytes
SHA-256: 6d13e73e85a502a13969f6a5eaecd0b275a0868c045f80b7d64ed55d70678261