Malicious PDF — malware analysis report

Static analysis result for SHA-256 3228acba46d5ba50…

MALICIOUS

PDF

133.1 KB Created: 2022-07-19 01:38:48 +00:00 Authoring application: peemar (via PDF Master 1.0.1) First seen: 2026-05-17
MD5: a1a6e7b02ee5de615cd4ce04397e6331 SHA-1: d2ef6651594c8e2bdea2f81d1cf3d92655573eb0 SHA-256: 3228acba46d5ba50cf27fb0ea879283762826f79958b2994bf1689b697bbde00
249 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0008

Heuristics 8

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Cracked-software lure uses shortlink/download gateway critical PDF_CRACKED_SOFTWARE_SHORTLINK_LURE
    PDF visible text advertises a crack, serial number, archive, or pirated-software download and pairs it with a shortlink or encoded download gateway. This is a high-confidence social-engineering carrier for unwanted software or droppers; the PDF itself is not a parser exploit.
  • Cracked-software lure uses download-gateway redirectors high PDF_CRACKED_SOFTWARE_REDIRECTOR_LINK_FARM
    PDF contains multiple cracked-software/keygen/serial-key lure links together with long encoded download-gateway URLs or known crack-download redirector hosts. This is stronger than generic piracy vocabulary: the document is an SEO lure that funnels users through redirect/download infrastructure commonly used for adware, unwanted software, or droppers.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • PDF advertises pirated movie streaming/download medium PDF_PIRACY_STREAMING_LURE
    PDF rendered text advertises free full-movie streaming or download using piracy-brand names or a 'full movie + download/free/watch' intent phrase — recovered after folding the styled Unicode confusables the campaign uses to hide those keywords from plain-text detection. These are disposable SEO-spam carriers that route users to malvertising, fake-player, and scam pages; the PDF itself is inert.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rocketcarrental.com/dulls/duty.epimerase.gennaio/ZG93bmxvYWR8R2cyTVRWMFpYQjhmREUyTlRnd01EWTJPVGw4ZkRJMU9UQjhmQ2hOS1NCWGIzSmtjSEpsYzNNZ1cxaE5URkpRUXlCV01pQlFSRVpk/illustrious/habours/negates/MTIgWWVhcnMgQSBTbGF2ZSBEb3dubG9hZCA3MjBwIEluIEhpbmRpMTI/ PDF link annotation
    • https://baitjadati.com/wp-content/uploads/2022/07/bangextremesiteriptorrent_downloader.pdfIn PDF document text
    • http://www.oscarspub.ca/xforce-keygen-autocad-plant-3d-2011-link/In PDF document text
    • http://www.superlisten.dk/wp-content/uploads/2022/07/Beachhead_2000_activation_code_and_serial_number.pdfIn PDF document text
    • https://www.vedraivedrai.eu/wp-content/uploads/2022/07/D16_Group_Drumazon_VSTi_V1_4_0_Incl_PORTABLE_Keygen_AiRrar__21.pdfIn PDF document text
    • https://www.sparegistrar.com/wp-content/uploads/2022/07/quobsant.pdfIn PDF document text
    • https://monkeyforestubud.id/wp-content/uploads/2022/07/AutoCAD_LT_2006_Portable_Torrent.pdfIn PDF document text
    • https://momentsofjoys.com/2022/07/19/acordes-de-cuatro-pdf-downloadl-better/In PDF document text
    • https://firis.pl/220-acapella-samples-pack-rar-conecta-biologia-ser/In PDF document text
    • https://knowthycountry.com/wp-content/uploads/2022/07/pacixeni-1.pdfIn PDF document text
    • https://matzenab.se/wp-content/uploads/2022/07/Schemaplic_v30_crack_torrent__btjunkie.pdfIn PDF document text
    • https://youfee.de/wp-content/uploads/2022/07/Nvidia_Physx_7_REPACK_Download_Medal_Of_Honor_Airborne-1.pdfIn PDF document text
    • https://www.flordechanar.cl/wp-content/uploads/2022/07/dargilm.pdfIn PDF document text
    • https://azizeshop.com/wp-content/uploads/2022/07/modevass.pdfIn PDF document text
    • https://in-loving-memory.online/oprtbox-office-password-recovery-toolbox-crack-best/In PDF document text
    • https://www.danke-eltern.de/wp-content/uploads/2022/07/Avcs_Ultra_Album_Studio_Full_Crack_Software_19_WORK.pdfIn PDF document text
    • https://big-plate.de/2022/07/19/hth-gold-rld-february2013/In PDF document text
    • https://www.skiptracingleads.com/wp-content/uploads/2022/07/imojwaro-1.pdfIn PDF document text
    • https://hogeorgia.com/wp-content/uploads/2022/07/Lenovo_Windows_7_Pci_Serial_Port_Driver_LINK.pdfIn PDF document text
    • https://mammothminerockshop.com/yu-gi-oh-gx-power-chaos-chazz-vainglory-modpc-key/In PDF document text
    • https://amtothepm.com/wp-content/uploads/2022/07/Crack_Topckit_2012_Serial_Number.pdfIn PDF document text
    • http://www.superlisten.dk/wp-In PDF document text
    • https://www.vedraivedrai.eu/wp-content/uploads/2022/07/D16_Group_Drumazon_VSTi_V1_4_0_Incl_PIn PDF document text
    • https://youfee.de/wp-In PDF document text
    • https://www.danke-eltern.de/wp-In PDF document text
    • https://hogeorgia.com/wp-In PDF document text
    • http://rocketcarrental.com/dulls/duty.epimerase.gennaio/zg93bmxvywr8r2cytvrwmfpyqjhmreuytlrnd01ewtjpvgw4zkrjmu9uqjhmq2hos1ncwgizsmtjsepsyznnz1cxae5urkpruxlcv01pqlfsrvpk/illustrious/habours/negates/mtigwwvhcnmgqsbtbgf2zsbeb3dubg9hzca3mjbwieluiehpbmrpmti/In PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text
🗂 Part of campaign: secureserver.net 1471 samples

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_009_off00019e06.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x19E06 119072 bytes
SHA-256: df221e87b81d1531cafdadb6c09a602e9f604d1baf0a17bbd350cbb83baa06f7
font_00_sfnt_off00001df8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1DF8 85984 bytes
SHA-256: 9ec03c428506d8ad0487ad2c1624ae9eb020311e2b0855f048f7712ab0c2c11f
font_01_sfnt_off0000aa12.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAA12 83036 bytes
SHA-256: 6d13e73e85a502a13969f6a5eaecd0b275a0868c045f80b7d64ed55d70678261