MALICIOUS
174
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0013
Heuristics 6
-
Cracked-software lure uses shortlink/download gateway critical PDF_CRACKED_SOFTWARE_SHORTLINK_LUREPDF visible text advertises a crack, serial number, archive, or pirated-software download and pairs it with a shortlink or encoded download gateway. This is a high-confidence social-engineering carrier for unwanted software or droppers; the PDF itself is not a parser exploit.
-
Cracked-software lure uses download-gateway redirectors high PDF_CRACKED_SOFTWARE_REDIRECTOR_LINK_FARMPDF contains multiple cracked-software/keygen/serial-key lure links together with long encoded download-gateway URLs or known crack-download redirector hosts. This is stronger than generic piracy vocabulary: the document is an SEO lure that funnels users through redirect/download infrastructure commonly used for adware, unwanted software, or droppers.
-
PDF links to a cracked-software download doorway (base64-obfuscated) high PDF_CRACKED_SOFTWARE_DOWNLOAD_DOORWAYPDF's embedded link hides a pirated-software title as a base64 blob inside the URL path/query (and/or carries the ``download|`` doorway-template marker), rather than in visible text. This is a TCPDF-generated SEO doorway that ranks for software-piracy searches and funnels users to fake 'crack/keygen' download pages distributing adware, potentially-unwanted programs, or droppers. The base64 encoding is deliberate obfuscation to evade plaintext lure rules; the PDF itself carries no parser exploit — the risk is the linked crack-download destination.
-
PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LUREPDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://godsearchs.com/caliphate.finalising?idlers=meryl&R29ibGluIEdlYXJzaG9wR29=frist&gravesite=/suspiciousness.ZG93bmxvYWR8Y0IxYzJadk9YeDhNVFkxT0RJeU1EZzJObng4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA PDF link annotation
- https://p2p-tv.com/kenshi-original-soundtrack-hack-patch-download-win-mac-latest/In PDF document text
- https://farmaciacortesi.it/new-yankee-9-the-evil-spellbook-cheat-code-with-product-key-download-win-mac/In PDF document text
- http://granadaproperti.com/?p=105848In PDF document text
- http://yogaapaia.it/archives/60936In PDF document text
- http://kolatia.com/?p=18052In PDF document text
- https://c-secure.fi/wp-content/uploads/2022/07/Troll_Hunter_VR_Hacked_.pdfIn PDF document text
- https://www.st-wilfrids.bkcat.co.uk/wp-content/uploads/2022/07/kanokaid.pdfIn PDF document text
- http://shoplidaire.fr/?p=166628In PDF document text
- https://silkfromvietnam.com/pyramid-vr-hack-full-version-free-download-win-mac-updated/In PDF document text
- https://buzau.org/wp-content/uploads/INDIKA-1.pdfIn PDF document text
- http://it-labx.ru/?p=86494In PDF document text
- https://wanoengineeringsystems.com/bbtag-dlc-color-pack-1-crack-patch-latest/In PDF document text
- https://expressionpersonelle.com/wp-content/uploads/2022/07/The_Smurfs_Mission_Vileaf_Preorder_Bonuses.pdfIn PDF document text
- https://bestrest.rest/wp-content/uploads/2022/07/Closers_Platinum_Package.pdfIn PDF document text
- https://www.solaiocompound.it/wp-content/uploads/2022/07/Expansion__Crusader_Kings_II_Sons_Of_Abraham_Cheat_Code_Torrent_Free.pdfIn PDF document text
- https://ameppa.org/wp-content/uploads/2022/07/Unending_War_GrandStrategy_Chess.pdfIn PDF document text
- https://marijuanabeginner.com/undeads-vs-humans-keygen-crack-setup/In PDF document text
- https://cecj.be/��������������-hacked-torrent-latest/In PDF document text
- http://mysquare.in/?p=In PDF document text
- https://www.theblender.it/nyanco-channel-soundtrack-trainer-for-pc/In PDF document text
- http://godsearchs.com/caliphate.finalising?idlers=meryl&r29ibgluiedlyxjzag9wr29=frist&gravesite=/suspiciousness.zg93bmxvywr8y0ixyzjadk9yedhnvfkxt0rjeu1ezzjobng4twpvnu1iedhlrtbwsuzkdmntundjbvz6y3lcyldfmu1vbejesuzzeulgqkvsbdaIn PDF document text
- https://cecj.be/ʊ字大冒险-hacked-torrent-latest/In PDF document text
- http://www.tcpdf.orgIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://www.aiim.org/pdfa/ns/extension/In PDF document text
- http://www.aiim.org/pdfa/ns/schema#In PDF document text
- http://www.aiim.org/pdfa/ns/property#In PDF document text
- http://www.aiim.org/pdfa/ns/id/In PDF document text
🗂 Part of campaign:
secureserver.net
1471 samples
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000588e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x588E | 84692 bytes |
SHA-256: 8f98cad6e8dee01884d4a2770871c6a63547c7357c7e57d1959c091ab70c8b15 |
|||
font_01_sfnt_off0000e11c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE11C | 83036 bytes |
SHA-256: 6d13e73e85a502a13969f6a5eaecd0b275a0868c045f80b7d64ed55d70678261 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.