Malicious PDF — malware analysis report

Static analysis result for SHA-256 89f28d72108fcb21…

MALICIOUS

PDF

131.6 KB Created: 2022-07-15 22:12:27 +00:00 Authoring application: hampjess (via PDF Master 1.0.1) First seen: 2026-05-01
MD5: 4ae47d1d5227bcf6b4d57111cce42a01 SHA-1: a449a5e1b555dd3a8c24687d4a22c8727547dbf9 SHA-256: 89f28d72108fcb218ae05c31f41348e976c77e9eecc2ef0bef862d722ffa1c87
104 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0003

Heuristics 4

  • Cracked-software lure uses shortlink/download gateway critical PDF_CRACKED_SOFTWARE_SHORTLINK_LURE
    PDF visible text advertises a crack, serial number, archive, or pirated-software download and pairs it with a shortlink or encoded download gateway. This is a high-confidence social-engineering carrier for unwanted software or droppers; the PDF itself is not a parser exploit.
  • PDF links to a cracked-software download doorway (base64-obfuscated) high PDF_CRACKED_SOFTWARE_DOWNLOAD_DOORWAY
    PDF's embedded link hides a pirated-software title as a base64 blob inside the URL path/query (and/or carries the ``download|`` doorway-template marker), rather than in visible text. This is a TCPDF-generated SEO doorway that ranks for software-piracy searches and funnels users to fake 'crack/keygen' download pages distributing adware, potentially-unwanted programs, or droppers. The base64 encoding is deliberate obfuscation to evade plaintext lure rules; the PDF itself carries no parser exploit — the risk is the linked crack-download destination.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://starsearchtool.com/agenda/baaack/felicia/germination.obersved/secretion.tatty/ZG93bmxvYWR8bTJuYVRSdE5YeDhNVFkxTnpnek1EUXlOWHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA.RWxkZW4gUmluZwRWx PDF link annotation
    • http://starsearchtool.com/agenda/baaack/felicia/germination.obersved/secretion.tatty/zg93bmxvywr8btjuyvrsde5yedhnvfkxtnpnek1euxlowhg4twpvnu1iedhlrtbwsuzkdmntundjbvz6y3lcyldfmu1vbejesuzzeulgqkvsbda.rwxkzw4gumluzwrwxIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_010_off0001b3ea.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1B3EA 119072 bytes
SHA-256: df221e87b81d1531cafdadb6c09a602e9f604d1baf0a17bbd350cbb83baa06f7
font_00_sfnt_off00003632.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3632 84712 bytes
SHA-256: 079b731633111309e4017d95dd1ef2a4c4ac88fae19158da6b788974a13ee690
font_01_sfnt_off0000bec1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBEC1 83412 bytes
SHA-256: 1d3aa29a20ed319ee76aa87fa4eec8fcfc56de2976c6c0c36c5ceb2ed42ebfa3