Malicious PDF — malware analysis report

Static analysis result for SHA-256 941e50cdd3e4eeb2…

MALICIOUS

PDF

95.7 KB Created: 2022-06-11 18:52:59 +02:00 Authoring application: goncanto (via PDF Master 1.0.1) First seen: 2026-06-12
MD5: 0eeb21e1f55c7796e52c7930722cd3f6 SHA-1: 1c668eaf7018da488a077e98d5746fd41526d654 SHA-256: 941e50cdd3e4eeb27dc647805efe81ce7246ce6cd5471ed65f19ca2d1525f3d4
64 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0052

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/flukes/ZG93bmxvYWR8Y3Y2TVRCaU5taDhmREUyTlRRNE9UTXhPVEY4ZkRJMU9UQjhmQ2hOS1NCWGIzSmtjSEpsYzNNZ1cxaE5URkpRUXlCV01pQlFSRVpk/.SSBBbSBTaW5naCBtYXJhdGhpIG1vdmllIEZVTEwgVmVyc2lvbiBkb3dubG9hZASSB/.hague.kennel?transplanting=curtis=paulsen.rodale PDF link annotation
    • https://www.5etwal.com/wp-content/uploads/2022/06/IGI_2_Covert_Strike_Version_2003GOG.pdfIn PDF document text
    • https://rastadream.com/wp-content/uploads/2022/06/kadmneda.pdfIn PDF document text
    • https://eqcompu.com/2022/06/11/extra-quality-c3520-flash-loader-7-5-4-csc-v0-2-citrus-lite/In PDF document text
    • https://cdn.geeb.xyz/upload/files/2022/06/mcRicKLw9IjLSamr6iXw_11_4c6e7b32fd0f44db50b631c4d3396cbf_file.pdfIn PDF document text
    • https://surprisemenow.com/hd-online-player-download-the-jane-austen-book-club-m-verified/In PDF document text
    • https://guatemall.club/wp-content/uploads/2022/06/erwchr.pdfIn PDF document text
    • https://lfbridge.com/upload/files/2022/06/v7LxuDlRQ3qncvDNHe4V_11_4c6e7b32fd0f44db50b631c4d3396cbf_file.pdfIn PDF document text
    • https://www.onk-group.com/wp-content/uploads/2022/06/frelytt.pdfIn PDF document text
    • https://salty-retreat-13688.herokuapp.com/anndart.pdfIn PDF document text
    • http://mysleepanddreams.com/pokemon-hentai-version-game-exclusive-download-2/In PDF document text
    • https://sarahebott.org/fatxplorer-2-5-1-14449-serials-m/In PDF document text
    • https://o-etxt.ru/wp-content/uploads/2022/06/Jure_Radic_Betonske_Konstrukcije_Pdf_Download.pdfIn PDF document text
    • https://5e19.com/wp-content/uploads/2022/06/Quest_Arrow_Addon_Wow.pdfIn PDF document text
    • https://careerlineup.com/wp-content/uploads/2022/06/Stardock_Start10_10_PreActivated_4realtorrentz_2021.pdfIn PDF document text
    • http://sharedsuccessglobal.com/marketplace/upload/files/2022/06/jirD2CbA86BwVRVRtEFZ_11_c7844e64f9d7e7d98ac2b3a585b3b7ae_file.pdfIn PDF document text
    • https://www.campingcar.ch/advert/download-pdf-tex-willer-2015/In PDF document text
    • https://www.indianhomecook.com/wp-content/uploads/2022/06/Steven_Universe_Save_the_LightPLAZA_hack_tool_download.pdfIn PDF document text
    • http://wp2-wimeta.de/dmelect-2012-descargar-57-39-exclusive/In PDF document text
    • http://www.momshuddle.com/upload/files/2022/06/uq1Qm1GUyrpLIcjs23xW_11_c7844e64f9d7e7d98ac2b3a585b3b7ae_file.pdfIn PDF document text
    • https://soundcollapse.altervista.org/advert/lal-kamal-neel-kamal-bengali-movie-portable/In PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off0000108a.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x108A 120140 bytes
SHA-256: a217f12862e0ff75203bdd4136ca0d68471050be46bb09aed5306898926ffdd4
stream_006_off00010009.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x10009 119072 bytes
SHA-256: df221e87b81d1531cafdadb6c09a602e9f604d1baf0a17bbd350cbb83baa06f7