Malicious PDF — malware analysis report

Static analysis result for SHA-256 205e107324b92db0…

MALICIOUS

PDF

85.3 KB Created: 2022-06-10 04:35:58 +02:00 Authoring application: filroza (via PDF Master 1.0.1) First seen: 2026-07-20
MD5: 24b18186a9af8718190dc43433dbfb35 SHA-1: efcb1dab8fb782e7dae2511b230712d2994e7985 SHA-256: 205e107324b92db05dd9cce268a9ec84da0056c18cfb4053b20e968002568795
234 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0095

Heuristics 7

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Cracked-software lure uses shortlink/download gateway critical PDF_CRACKED_SOFTWARE_SHORTLINK_LURE
    PDF visible text advertises a crack, serial number, archive, or pirated-software download and pairs it with a shortlink or encoded download gateway. This is a high-confidence social-engineering carrier for unwanted software or droppers; the PDF itself is not a parser exploit.
  • Cracked-software lure uses download-gateway redirectors high PDF_CRACKED_SOFTWARE_REDIRECTOR_LINK_FARM
    PDF contains multiple cracked-software/keygen/serial-key lure links together with long encoded download-gateway URLs or known crack-download redirector hosts. This is stronger than generic piracy vocabulary: the document is an SEO lure that funnels users through redirect/download infrastructure commonly used for adware, unwanted software, or droppers.
  • PDF links to a cracked-software download doorway (base64-obfuscated) high PDF_CRACKED_SOFTWARE_DOWNLOAD_DOORWAY
    PDF's embedded link hides a pirated-software title as a base64 blob inside the URL path/query (and/or carries the ``download|`` doorway-template marker), rather than in visible text. This is a TCPDF-generated SEO doorway that ranks for software-piracy searches and funnels users to fake 'crack/keygen' download pages distributing adware, potentially-unwanted programs, or droppers. The base64 encoding is deliberate obfuscation to evade plaintext lure rules; the PDF itself carries no parser exploit — the risk is the linked crack-download destination.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/approach/U3VtbWVyIEhlYXQgQmVhY2ggVm9sbGV5YmFsbCBQczIgSXNvIFRvcnJlbnQU3V/ZG93bmxvYWR8YUMzTlRCaGNueDhNVFkxTkRjNE1EZzNPWHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA/carsten/incubate.meru/verizon/supersized/madisonville PDF link annotation
    • http://sourceofhealth.net/wp-content/uploads/2022/06/terkamm.pdfIn PDF document text
    • https://seisystem.it/wp-content/uploads/2022/06/Indiana_Jones_and_the_Staff_of_Kings_USA__The_Game_Play.pdfIn PDF document text
    • https://vega-eu.com/wp-content/uploads/2022/06/Free_Download_Craagle_40_UPD.pdfIn PDF document text
    • https://colourmypot.com/wp-content/uploads/Wic_Reset_Utility_V_3_00_Reset_Key_Torrent.pdfIn PDF document text
    • https://wanaly.com/upload/files/2022/06/nFEZjEGNI6teSATeuyvX_10_31edf81b57d8578310824d4bdaaeca7c_file.pdfIn PDF document text
    • https://fitenvitaalfriesland.nl/need-for-speed-rivals-setup-exe/In PDF document text
    • http://marqueconstructions.com/wp-content/uploads/2022/06/God_of_War_SERIAL_KEY_GENERATOR.pdfIn PDF document text
    • https://technospace.co.in/upload/files/2022/06/2pl5Cnsoxxm6vpL4D2yy_10_31edf81b57d8578310824d4bdaaeca7c_file.pdfIn PDF document text
    • https://apolloinstitute.com.au/moodle/blog/index.php?entryid=1139In PDF document text
    • https://businessbooster.page/wp-content/uploads/2022/06/sealkaf.pdfIn PDF document text
    • https://dashiofficial.com/wp-content/uploads/2022/06/dalmrayd.pdfIn PDF document text
    • https://www.caving.ie/wp-content/uploads/valulri.pdfIn PDF document text
    • https://cambodiaonlinemarket.com/wp-content/uploads/2022/06/DGS_RAMSETE_III_V905LNDrar31.pdfIn PDF document text
    • https://beddinge20.se/wp-content/uploads/2022/06/AmpleSoundAGMLibraryR2R_Keygen_Setup_Freel.pdfIn PDF document text
    • https://www.cbdexpress.nl/wp-content/uploads/lisrel88downloadfullversion.pdfIn PDF document text
    • http://www.ecomsrl.it/toro-aladdin-dongles-monitor-64-bit-top/In PDF document text
    • https://taavistea.com/wp-content/uploads/2022/06/APACHE_AIR_ASSAULT_Activation_Code_Pc_Gamerar.pdfIn PDF document text
    • https://insightkorea.or.kr/blog/index.php?entryid=3566In PDF document text
    • https://www.designonline-deco.com/wp-content/uploads/2022/06/Teksoft_Kts_Crack.pdfIn PDF document text
    • https://gravesendflorist.com/istorijos-vadovelis-10-klasei-pdf-12/In PDF document text
    • http://evacdir.com/approach/u3vtbwvyiehlyxqgqmvhy2ggvm9sbgv5ymfsbcbqczigsxnvifrvcnjlbnqu3v/zg93bmxvywr8yumztlrcagnuedhnvfkxtkrjne1ezznpwhg4twpvnu1iedhlrtbwsuzkdmntundjbvz6y3lcyldfmu1vbejesuzzeulgqkvsbda/carsten/incubate.meru/verizon/supersized/madisonvilleIn PDF document text
    • https://beddinge20.se/wp-content/uploads/2022/06/amplesoundagmlibraryr2r_keygen_setup_freel.pdfIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000018bc.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x18BC 126044 bytes
SHA-256: c9dd668daa1e895826ae872b13fecc923e40619bc3c6f1cb5019723576470605