PDF static analysis report

Static analysis result for SHA-256 a4e153ff50480f54…

SUSPICIOUS

PDF

125.3 KB Created: 2022-06-09 23:15:28 +02:00 Authoring application: narcarl (via PDF Master 1.0.1) First seen: 2022-07-15
MD5: 899ff85c5c5c9993bc521bc27c2331f0 SHA-1: 5ad711c4e4583b655cbdd263bf34d50b7442c3a4 SHA-256: a4e153ff50480f5443dca31f9c91b6ae9e5a3b98782794e6e72151b7ec1dbfd7
34 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0296

Heuristics 3

  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://evacdir.com/blackest/bodybag.counting.pizzeria/ZG93bmxvYWR8azJRWm05MVpIeDhNVFkxTkRjNE1EYzROM3g4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk/saltinbucca.unfounded?microcapsules=U25pcGVyIEVsaXRlIFYyIFBjIEdhbWUgV2l0aCBDcmFjayBCeSBTa2lkcm93IENyYWNrU25 PDF link annotation
    • https://cine-africain.com/olislav/keygen-link-download-asure-id-7/In PDF document text
    • http://www.barberlife.com/upload/files/2022/06/R2qt1WNcgKanjIiRbMMf_09_bf3b4988a7f793c1fe3cd60c2088047a_file.pdfIn PDF document text
    • https://rodillosciclismo.com/sin-categoria/touchscan-license-key-better/In PDF document text
    • https://limitless-headland-46686.herokuapp.com/cojtama.pdfIn PDF document text
    • https://bodhirajabs.com/babylon-pro-10-offline-installer-with-serial-17l-randyamuv/In PDF document text
    • https://ithinksew.net/advert/cambridge-english-exams-listening/In PDF document text
    • http://bookmarkwebs.com/upload/files/2022/06/tgHmNnXgWqZdiCNZGVR8_09_bf3b4988a7f793c1fe3cd60c2088047a_file.pdfIn PDF document text
    • https://awinkiweb.com/frsrpartigeneralrulespdffreedownload-link/In PDF document text
    • https://flagonsworkshop.net/upload/files/2022/06/6GnuwNAGqFWZE7kEVEIm_09_af5cfcd6280da41911870fd14bc61103_file.pdfIn PDF document text
    • https://suchanaonline.com/trackmania-united-forever-2-11-26-keygen-generator-work/In PDF document text
    • https://worlegram.com/upload/files/2022/06/Cx4wgs58oZ9YYcLcmaYA_09_bf3b4988a7f793c1fe3cd60c2088047a_file.pdfIn PDF document text
    • https://community.tccwpg.com/upload/files/2022/06/kObu1HrSNETsWVy46l1C_09_e48ba2ff0977d086313a93c5e68db2c0_file.pdfIn PDF document text
    • https://www.hony.nl/in-de-collectie/midifile-optimizer-7-dongle-crack/In PDF document text
    • https://bakedenough.com/karizmaalbum12x36psdweddingbackground/In PDF document text
    • https://buycoffeemugs.com/plagiarism-checker-x-2018-pro-v6-0-6-seupirate-setup-verified-free/In PDF document text
    • https://surprisemenow.com/?p=37005In PDF document text
    • http://formeetsante.fr/audiolounge-urs-wiesendanger-rhodes-affair-2-full-better-vst-au-win-osx-x86-x64/In PDF document text
    • https://eventgb.com/2022/06/09/passfab-4winkey-7-1-0-8-crack-with-keygen-full-version-download-is-here/In PDF document text
    • https://binlentcentspookul.wixsite.com/brixinmensick/post/euro-truck-simulator-2-v1-22-2s-29-dlc-2-click-run-euro-truck-simulator-2-v1-22-2s-29-dlc-2-41In PDF document text
    • https://narilecompfodoor.wixsite.com/contimema/post/kvisoft-flipbook-maker-pro-4-3-4-portable-serial-keyIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000129c.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x129C 120140 bytes
SHA-256: a217f12862e0ff75203bdd4136ca0d68471050be46bb09aed5306898926ffdd4