Malicious PDF — malware analysis report

Static analysis result for SHA-256 4e3110c51cb9b66f…

MALICIOUS

PDF

116.1 KB Created: 2022-09-09 13:27:53 +00:00 Authoring application: hamfaus (via PDF Master 1.0.1) First seen: 2026-06-19
MD5: 6b88029ea2d01740f8011660680dbe59 SHA-1: 84d13b2a50cf8dc061458ae4e985db96c65deced SHA-256: 4e3110c51cb9b66f155d880adde2cdafbe7965c46fb2bd184f32ae1db0569b17
64 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0009

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://signforcover.com/barbary?Y29kIG13MiBib251cyBtYXBzIGZyZWUgZG93bmxvYWQY29=capitated&gaylords=&billboards=mammut&ZG93bmxvYWR8SXc4T0dweVozeDhNVFkyTWpZNE1ETTVNSHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA=snowmobiles PDF link annotation
    • http://wp2-wimeta.de/download-zeus-botnet-free-1-best/In PDF document text
    • https://secure-forest-46733.herokuapp.com/attlanni.pdfIn PDF document text
    • https://embrion-ivf.com/wp-content/uploads/2022/09/janfil.pdfIn PDF document text
    • https://desolate-escarpment-79201.herokuapp.com/alvkal.pdfIn PDF document text
    • https://lsvequipamentos.com/wp-content/uploads/2022/09/Handycafe_3414_Cracked_Snper.pdfIn PDF document text
    • https://radiant-savannah-39681.herokuapp.com/caiswort.pdfIn PDF document text
    • https://fierce-eyrie-96983.herokuapp.com/ansi_vita_51_1_pdf_reliability_prediction_pdf.pdfIn PDF document text
    • https://arcane-scrubland-42990.herokuapp.com/aldokaiy.pdfIn PDF document text
    • https://www.answerwatcher.com/wp-content/uploads/2022/09/HD_Online_Player_Tell_No_One_2006_Br_Rip_1080p_Movie_.pdfIn PDF document text
    • http://cennews.in/?p=19126In PDF document text
    • http://mysquare.in/?p=In PDF document text
    • https://bestrest.rest/wp-content/uploads/2022/09/Malwarebytes_AntiMalware_Corporate_18011011_Multilingual_cra.pdfIn PDF document text
    • https://coi-csod.org/wp-content/uploads/2022/09/Maze_Runner_Movie_Download_EXCLUSIVE_High_Compressed.pdfIn PDF document text
    • https://limitless-everglades-30006.herokuapp.com/errbart.pdfIn PDF document text
    • https://sagitmymindasset.com/uncategorized/lekar-hum-deewana-dil-movie-1-1080p/In PDF document text
    • http://media.snuff24.se/2022/09/cleabro.pdfIn PDF document text
    • https://atompublishing.info/wp-content/uploads/2022/09/keyliol.pdfIn PDF document text
    • https://peaceful-beyond-46960.herokuapp.com/vastuguna_deepika_pdf_download.pdfIn PDF document text
    • https://nameme.ie/machines-electriques-kostenko-pdf-download-new/In PDF document text
    • http://contabeissemsegredos.com/hd-online-player-descargar-conciertos-completos-en-hd-__top__/In PDF document text
    • https://www.answerwatcher.com/wp-In PDF document text
    • https://bestrest.rest/wp-In PDF document text
    • https://coi-csod.org/wp-In PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text