Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d3c87a1e1988d0e…

MALICIOUS

PDF

122.0 KB Created: 2022-09-09 10:10:35 +00:00 Authoring application: manphi (via PDF Master 1.0.1) First seen: 2026-06-14
MD5: 245c4a797ef08ac79b1655df576801db SHA-1: 99c4c0d7c7049c2c66147adbd480efd96bbb2f91 SHA-256: 0d3c87a1e1988d0ea4d56fe40b2f2ba1b15367ac28418e230e6521bba6211d2d
94 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0006

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://hardlyfind.com/crowchild.Q3JhY2sgQ2FycnlNYXAgViAyIDMQ3J/definiteness/fergie/gosden/ejection/?ZG93bmxvYWR8QWk5Tm1jMGRueDhNVFkyTWpZNE1ETTVNSHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA=.hippies PDF link annotation
    • https://lifelonglessons.org/wp-content/uploads/2022/09/HyperdimensionNeptuniaReBirth1DeluxePackDELUXEfullcrackkey.pdfIn PDF document text
    • https://antoinevanaalst.com/wp-content/uploads/2022/09/Adobe_Photoshop_92_CS2_Final_keyGenzip_download-2.pdfIn PDF document text
    • https://egypt-aquarium.com/advert/sid-meiers-railroads-patch-v1-10-no-cd-link-crack-v1-10/In PDF document text
    • https://bullygirlmagazine.com/advert/the-message-of-islam-full-better-movie-in-hindi/In PDF document text
    • https://www.siriusarchitects.com/advert/hum-tum-2004-1080p-bluray-x264-hindi-aac-etrg/In PDF document text
    • https://stark-woodland-74380.herokuapp.com/lindjam.pdfIn PDF document text
    • https://cambodiaonlinemarket.com/la-sabiduria-del-cuerpo-cannon-pdf/In PDF document text
    • http://shop.chatredanesh.ir/?p=120008In PDF document text
    • https://teenmemorywall.com/reclaime-pro-v0-196-dvt-keygen-hot/In PDF document text
    • https://koenigthailand.com/wp-content/uploads/2022/09/those_nights_at_fredbears_download.pdfIn PDF document text
    • https://xn--80aagyardii6h.xn--p1ai/batman-bad-blood-full-movie-download-mp4-18-best-amp/In PDF document text
    • https://thetopteninfo.com/wp-content/uploads/2022/09/Filemaker_Pro_12_Advanced_Crack_28_FULL.pdfIn PDF document text
    • https://ayoikut.com/advert/arkaos-vj-3-5-crack-2021/In PDF document text
    • https://kcmuslims.com/advert/formato-afil-02-imss-editable-pdf-rar/In PDF document text
    • http://fabianozan.com/?p=21931In PDF document text
    • http://www.tunlive.com/wp-content/uploads/naruto_shippuden_season_13_720p_download.pdfIn PDF document text
    • http://saddlebrand.com/wp-content/uploads/2022/09/Nostradamus_Book_Of_Prophecies_Pdf_Free_Download_TOP.pdfIn PDF document text
    • https://missionmieuxetre.com/2022/09/09/mise-a-jour-cartes-rns-310-blaupunkt-2013-v5/In PDF document text
    • https://radiant-ravine-43142.herokuapp.com/Solucionario_Ingenieria_Economica_Guillermo_Baca_Currea.pdfIn PDF document text
    • https://www.hradkacov.cz/wp-content/uploads/2022/09/hanvale-1.pdfIn PDF document text
    • https://lifelonglessons.org/wp-content/uploads/2022/09/HyperdimensionNeptuniaRIn PDF document text
    • https://antoinevanaalst.com/wp-content/uploads/2022/09/Adobe_Photoshop_92_CIn PDF document text
    • https://egypt-aquarium.com/advert/sid-meiers-railroads-patch-v1-10-no-cd-link-In PDF document text
    • https://bullygirlmagazine.com/advert/the-message-of-islam-full-better-movie-in-In PDF document text
    • https://www.siriusarchitects.com/advert/hum-tum-2004-1080p-bluray-x264-hindi-In PDF document text
    • https://koenigthailand.com/wp-In PDF document text
    • https://xn--80aagyardii6h.xn--p1ai/batman-bad-blood-full-movie-download-In PDF document text
    • https://thetopteninfo.com/wp-In PDF document text
    • http://www.tunlive.com/wp-In PDF document text
    • http://saddlebrand.com/wp-content/uploads/2022/09/Nostradamus_Book_Of_ProphIn PDF document text
    • https://missionmieuxetre.com/2022/09/09/mise-a-jour-cartes-In PDF document text
    • https://radiant-ravine-43142.herokuapp.com/Solucionario_Ingenieria_Economica_GIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text