Malicious PDF — malware analysis report

Static analysis result for SHA-256 72b91ee85dbdd5b2…

MALICIOUS

PDF

125.0 KB Created: 2022-07-01 07:05:09 +02:00 Authoring application: berfonz (via PDF Master 1.0.1) First seen: 2026-06-28
MD5: 39cd900b37c54e54a71de2a03ecd647e SHA-1: 75c154ae462ebbfe11b2eb4b911683292db84a03 SHA-256: 72b91ee85dbdd5b28683f7ffad797fccbe5d9b14fc062151ea6c46d9c2c17d6b
64 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0018

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dormister.com/crutchfield/jobsite/resolved/ZG93bmxvYWR8NXdhTTJZek4zeDhNVFkxTmpZME1EZ3hOM3g4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA/smells=suspicion/cGhvdG9zaG9wIDcuMCBmcmVlIGRvd25sb2FkIGZvciB3aW5kb3dzIDExIDY0IGJpdAcGh.hiltons PDF link annotation
    • https://roundabout-uk.com/adobe-photoshop-7-0-1-5/In PDF document text
    • https://ferramentariasc.com/2022/07/01/download-adobe-photoshop-8-1-0-full-version/In PDF document text
    • https://ozrural.com/index.php/advert/how-to-use-adobe-photoshop/In PDF document text
    • https://www.asv-ventabren.fr/wp-content/uploads/2022/07/how_to_install_Adobe_Photoshop_CS6.pdfIn PDF document text
    • http://www.studiofratini.com/wp-content/uploads/2022/07/Download_Photoshop_7_Full_Crack.pdfIn PDF document text
    • http://www.expo15online.com/advert/how-to-get-adobe-photoshop-free-dvd-iso/In PDF document text
    • http://www.over-scene.com/wp-content/uploads/2022/07/download_free_adobe_photoshop_cs3_portable.pdfIn PDF document text
    • https://akademiun.com/free-full-featured-photo-editing-application-in-android/In PDF document text
    • https://ryhinmobiliaria.co/wp-content/uploads/2022/07/American_State_Constitutions_The_Jacksonian_Era_18011840.pdfIn PDF document text
    • https://carolwestfineart.com/photoshop-installer-for-free/In PDF document text
    • http://www.rti-evaluation.org/calligraphy-brushes-free-download/In PDF document text
    • https://www.reperiohumancapital.com/system/files/webform/quamarb676.pdfIn PDF document text
    • https://armadalaptop.com/wp-content/uploads/2022/07/waymore.pdfIn PDF document text
    • https://talkin.co.ke/upload/files/2022/07/y4sy79DMaYgyxAbW9wkA_01_6b9b2666d9471443a9f15c494163d267_file.pdfIn PDF document text
    • https://eliottdupuy.com/5648531-2/In PDF document text
    • http://www.todaynewshub.com/wp-content/uploads/2022/07/Adobe_Photoshop_70_Full_Version_For_Windows_10.pdfIn PDF document text
    • https://ameppa.org/2022/07/01/download-pamflet-folder/In PDF document text
    • https://backrepdamagraipar.wixsite.com/tireadire/post/photoshop-lens-flares-brushesIn PDF document text
    • https://platform.blocks.ase.ro/blog/index.php?entryid=6475In PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000022a0.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x22A0 120140 bytes
SHA-256: a217f12862e0ff75203bdd4136ca0d68471050be46bb09aed5306898926ffdd4
font_01_sfnt_off0000d083.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD083 76772 bytes
SHA-256: 07ce6fea3c98bf59133021be55ce9147f9c26365efe580a2a4f82130ca697f54