PDF static analysis report

Static analysis result for SHA-256 67b88b00d6a952f8…

SUSPICIOUS

PDF

116.4 KB Created: 2022-07-04 05:13:50 +00:00 Authoring application: kesemey (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 3b70890d51e2667400c16a9b3e08feb0 SHA-1: 32e29f253d84cd4607974777c92b39b51a9c980d SHA-256: 67b88b00d6a952f8adbd1fb4d2a419fc9c84b2dbea59802c4377c7be2950af1d
34 Risk Score

Malware Insights

The PDF contains heuristics indicating it advertises cracked software and embeds external URIs. The primary embedded URI, http://signforcover.com/bentley/branagh=treason.VGV4dCBGaWxlIEpvaW5lcgVGV?crab=aaca&ZG93bmxvYWR8TlowTjNOcWVueDhNVFkxTmpnNU1qTTFNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA=senet, is likely part of a lure to download malicious content. The document body was unreadable, but the heuristics strongly suggest a software cracking lure.

Machine Learning

  • Nyx PDF Classifier clean score 0.0150

Heuristics 3

  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://signforcover.com/bentley/branagh=treason.VGV4dCBGaWxlIEpvaW5lcgVGV?crab=aaca&ZG93bmxvYWR8TlowTjNOcWVueDhNVFkxTmpnNU1qTTFNbng4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA=senet PDF link annotation
    • https://fantasyartcomics.com/wp-content/uploads/2022/07/GiliSoft_Movie_DVD_Copy_Crack_Activation_Code_With_Keygen_Free_Download_PCWindows_Updated_.pdfIn PDF document text
    • https://www.sandisfieldma.gov/sites/g/files/vyhlif1171/f/pages/planning_board_admin_asst._job_description.pdfIn PDF document text
    • https://www.dominionphone.com/carry-select-adder-download/In PDF document text
    • https://spacefather.com/andfriends/upload/files/2022/07/ODnupVo3veeGjfaaTzRp_04_6de37669b382dafeebc1330a8d60d4f8_file.pdfIn PDF document text
    • http://yogaapaia.it/archives/33622In PDF document text
    • https://glacial-shore-00038.herokuapp.com/ilbpanc.pdfIn PDF document text
    • http://fajas.club/?p=28601In PDF document text
    • https://www.voyavel.it/wp-content/uploads/2022/07/chaylat.pdfIn PDF document text
    • http://www.giffa.ru/who/e-adventure-crack-keygen-free-mac-win/In PDF document text
    • https://desolate-temple-84330.herokuapp.com/quyemm.pdfIn PDF document text
    • https://meuconhecimentomeutesouro.com/youtube-pal-crack-free-download/In PDF document text
    • https://mevoydecasa.es/webrender-crack-download-mac-win-2022-latest/In PDF document text
    • https://womss.com/scan-redirector-rdp-edition-2-0-01-crack/In PDF document text
    • http://www.antiquavox.it/xpize-incl-product-key-free-download/In PDF document text
    • http://compasscarrier.com/diskgetor-data-recovery-crack-win-mac/In PDF document text
    • https://ubipharma.pt/2022/07/04/direct-current-electrical-motor-model-crack-license-key-full-updated-2022/In PDF document text
    • https://sheltered-inlet-78551.herokuapp.com/vollear.pdfIn PDF document text
    • https://tchatche.ci/upload/files/2022/07/XLWbu9qTe6tri3UQKWDW_04_6de37669b382dafeebc1330a8d60d4f8_file.pdfIn PDF document text
    • https://landjohnbemoonsfil.wixsite.com/insijuro/post/deface-chrome-extension-download-pc-windowsIn PDF document text
    • http://diatutic.yolasite.com/resources/Filter-Foundry-Download-MacWin-Latest.pdfIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text