Malicious PDF — malware analysis report

Static analysis result for SHA-256 515e372f6d1b0476…

MALICIOUS

PDF

134.9 KB Created: 2022-06-11 08:31:05 +02:00 Authoring application: quarrej (via PDF Master 1.0.1) First seen: 2026-05-17
MD5: 180c6d0807ca0f96a55d7468ab70e57d SHA-1: 2c23a8982b4e98695ed29521103269ca801b7409 SHA-256: 515e372f6d1b0476d78dfb35b6170f1930057e586f5c337f63a2011dc1fb32be
194 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0015

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Cracked-software lure uses shortlink/download gateway critical PDF_CRACKED_SOFTWARE_SHORTLINK_LURE
    PDF visible text advertises a crack, serial number, archive, or pirated-software download and pairs it with a shortlink or encoded download gateway. This is a high-confidence social-engineering carrier for unwanted software or droppers; the PDF itself is not a parser exploit.
  • Cracked-software lure uses download-gateway redirectors high PDF_CRACKED_SOFTWARE_REDIRECTOR_LINK_FARM
    PDF contains multiple cracked-software/keygen/serial-key lure links together with long encoded download-gateway URLs or known crack-download redirector hosts. This is stronger than generic piracy vocabulary: the document is an SEO lure that funnels users through redirect/download infrastructure commonly used for adware, unwanted software, or droppers.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/bucket.QWRvYmUgSWxsdXN0cmF0b3IgQ0MgMjAxOCAyMi4wLjEuMjUzIFByZS1DcmFja2VkIC0gQ3JhY2t6U29mdCBkb3dubG9hZAQWR?immunology=ZG93bmxvYWR8SHoyWnpCa2JueDhNVFkxTkRnNU16RTVNWHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA&cormorant=disintecting= PDF link annotation
    • https://thetutorialworld.com/advert/download-microsoft-office-2007-full-version-highly-compressed-updated/In PDF document text
    • https://www.santafe-roma.it/wp-content/uploads/2022/06/Webcam_Soltech_300K_And_Generic.pdfIn PDF document text
    • https://www.fashionservicenetwork.com/wp-content/uploads/2022/06/Fundamentals_Of_Physical_Chemistry_Pdf_Solution_Manual_Maron.pdfIn PDF document text
    • https://goandwork.net/wp-content/uploads/2022/06/Virtual_Families_2__Our_Dream_House__full_PreCracked__Foxy_G.pdfIn PDF document text
    • https://bluesteel.ie/2022/06/11/swordfall-kingdoms-full-version-download-work/In PDF document text
    • https://vilabegir.com/wp-content/uploads/2022/06/milden.pdfIn PDF document text
    • https://darblo.com/wp-content/uploads/2022/06/Breeze_Systems_DSLR_Remote_Pro_2_5_3_Keygen_And_Serial.pdfIn PDF document text
    • https://supportingyourlocal.com/wp-content/uploads/2022/06/paxtalee.pdfIn PDF document text
    • https://365-ads.com/wp-content/uploads/2022/06/Addictive_Drums_Crack_Keygen_Torrent.pdfIn PDF document text
    • https://plugaki.com/upload/files/2022/06/kY3z9vuIpw7YKVpNZkED_11_53f0259432b1eaae6665619dce79839f_file.pdfIn PDF document text
    • https://heronetworktv.com/wp-content/uploads/2022/06/Statclass_2nd_Edition_Pdf.pdfIn PDF document text
    • https://lynonline.com/2022/06/11/vaalu-2015-hdrip-x264-700mb-esubs-tamil/In PDF document text
    • https://undergroundstudio.it/wp-content/uploads/2022/06/welschay.pdfIn PDF document text
    • https://wanoengineeringsystems.com/wp-content/uploads/2022/06/OfficeTabEnterprise1200228PreActivatedSerialKeykeygen.pdfIn PDF document text
    • https://ividenokkam.com/ads/advert/7tox-for-final-cut-pro-serial-number/In PDF document text
    • https://gabonbiota.org/portal/checklists/checklist.php?clid=8418In PDF document text
    • https://www.extremo.digital/wp-content/uploads/2022/06/DmC_Devil_May_Cry_BLES01698epub.pdfIn PDF document text
    • https://aapanobadi.com/2022/06/11/jewel-match-solitaire-download-crack-with-full-game-top/In PDF document text
    • https://rexclick.com/wp-content/uploads/2022/06/Janne_Da_Arc_Discography_Lossless.pdfIn PDF document text
    • https://b-labafrica.net/wp-content/uploads/2022/06/Starsector_Activation_Code_Generator_Fixed.pdfIn PDF document text
    • http://evacdir.com/bucket.qwrvymugswxsdxn0cmf0b3igq0mgmjaxocaymi4wljeumjuzifbyzs1dcmfja2vkic0gq3jhy2t6u29mdcbkb3dubg9hzaqwr?immunology=zg93bmxvywr8shoywnpca2juedhnvfkxtkrnnu16rtvnwhg4twpvnu1iedhlrtbwsuzkdmntundjbvz6y3lcyldfmu1vbejesuzzeulgqkvsbda&cormorant=disintecting=In PDF document text
    • https://365-ads.com/wp-content/uploads/2022/06/addictive_drums_crack_keygen_torrent.pdfIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off00000cf2.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xCF2 120140 bytes
SHA-256: a217f12862e0ff75203bdd4136ca0d68471050be46bb09aed5306898926ffdd4
font_01_sfnt_off0000bad5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBAD5 76772 bytes
SHA-256: 07ce6fea3c98bf59133021be55ce9147f9c26365efe580a2a4f82130ca697f54