Malicious PDF — malware analysis report

Static analysis result for SHA-256 51889150acbe17cb…

MALICIOUS

PDF

128.8 KB Created: 2022-06-22 00:45:57 +02:00 Authoring application: staclaza (via PDF Master 1.0.1) First seen: 2026-05-31
MD5: 82501fab15efc89951006e404eed4618 SHA-1: 6dab36a5aae5fe4cae220c74025badfbc4de2373 SHA-256: 51889150acbe17cb1e978057baaf670704bee989f91bdbc6bd9a17ca3e1384d3
234 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0005

Heuristics 8

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Cracked-software lure uses download-gateway redirectors high PDF_CRACKED_SOFTWARE_REDIRECTOR_LINK_FARM
    PDF contains multiple cracked-software/keygen/serial-key lure links together with long encoded download-gateway URLs or known crack-download redirector hosts. This is stronger than generic piracy vocabulary: the document is an SEO lure that funnels users through redirect/download infrastructure commonly used for adware, unwanted software, or droppers.
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/antiacids.martyr?ouest=&terraserver=percha&SGFkcm9uIE1vdXNlIERyaXZlciBJbmRpcgSGF=regionalism&ZG93bmxvYWR8OVU1TW1kdFpIeDhNVFkxTlRnME1qazRNWHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA=shelfish PDF link annotation
    • https://alternantreprise.com/non-classifiee/spymasterproapkcrackedapps/In PDF document text
    • https://smallprix.ro/static/uploads/2022/06/zuhbert.pdfIn PDF document text
    • https://cefcredit.com/wp-content/uploads/2022/06/generar_el_codigo_de_activacion_ecuakaraoke.pdfIn PDF document text
    • https://myhomemart.net/pocket-tanks-deluxe-v1-0-play-istai-1-0/diet-guide/In PDF document text
    • https://expressionpersonelle.com/army-of-two-the-40th-day-pc-game-torrent-download-hot/In PDF document text
    • http://www.ndvadvisers.com/?p=In PDF document text
    • http://www.medvedy.cz/wp-content/uploads/ysybkai.pdfIn PDF document text
    • https://rondaplaces.com/wp-content/uploads/2022/06/Fifa_15_FREE_Crack_V2_3dmrar_Download.pdfIn PDF document text
    • https://wintermarathon.de/advert/poutine/In PDF document text
    • https://www.olives-gonfond.com/?p=16011In PDF document text
    • https://nisharma.com/microsoft-office-standard-2013-product-key-generator/In PDF document text
    • https://jugueteriapuppe.cl/wp/wp-content/uploads/2022/06/Excel_Password_Recovery_Master_Crack_Registration_Code.pdfIn PDF document text
    • http://scamfie.com/?p=18027In PDF document text
    • https://triberhub.com/upload/files/2022/06/Eg6CrodrnFTfbZz7F3nf_21_47fc32672c1cd8837243b9268a5df6ba_file.pdfIn PDF document text
    • https://www.travellersvoice.ie/advert/download-kundli-software-for-windows-7-full-version-16l-cracked/In PDF document text
    • https://www.yourfootballshirt.com/wp-content/uploads/2022/06/Gabarito_Do_Estagio_F_De_Matematica_Do_Kumon.pdfIn PDF document text
    • https://www.webcard.irish/wp-content/uploads/2022/06/benike.pdfIn PDF document text
    • http://clubonlineusacasino.com/wp-content/uploads/2022/06/Recovertoolv20033l1224exe110mb.pdfIn PDF document text
    • http://connect.tg/wp-content/uploads/2022/06/tyanjai.pdfIn PDF document text
    • http://3.16.76.74/advert/caramembukapasswordrardengancmd/PDF link annotation
    • http://evacdir.com/antiacids.martyr?ouest=&terraserver=percha&sgfkcm9uie1vdxnlieryaxzlcibjbmrpcgsgf=regionalism&zg93bmxvywr8ovu1tw1kdfpiedhnvfkxtlrnme1qazrnwhg4twpvnu1iedhlrtbwsuzkdmntundjbvz6y3lcyldfmu1vbejesuzzeulgqkvsbda=shelfishIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text
🗂 Part of campaign: secureserver.net 1471 samples

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_009_off00002fad.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2FAD 120556 bytes
SHA-256: 917859fd449d94c59badc3c70df5fa4553e8e808ed01f280a7b6f74371c042ed
font_01_sfnt_off0000de41.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDE41 76772 bytes
SHA-256: 07ce6fea3c98bf59133021be55ce9147f9c26365efe580a2a4f82130ca697f54