Malicious PDF — malware analysis report

Static analysis result for SHA-256 a85b52b1ccb870a9…

MALICIOUS

PDF

53.0 KB Created: 2022-12-02 08:40:57 +00:00 Authoring application: birljaem (via mPDF 8.1.2) First seen: 2026-05-05
MD5: 12ddb9a6f5bf0b006f1abeab717a8e98 SHA-1: bbd90fb64f7e9aeca1a6d8da34f3b7958e9b63c7 SHA-256: a85b52b1ccb870a9b0fd55197e891539b48182aad1e76a9b438f305e7ad6360f
212 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0078

Heuristics 7

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Cracked-software lure uses shortlink/download gateway critical PDF_CRACKED_SOFTWARE_SHORTLINK_LURE
    PDF visible text advertises a crack, serial number, archive, or pirated-software download and pairs it with a shortlink or encoded download gateway. This is a high-confidence social-engineering carrier for unwanted software or droppers; the PDF itself is not a parser exploit.
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seachtop.com/enchants/?implemantation=overviewed.TmV0c3BvdCBQcm8gRnVsbCBDcmFjayAyMgTmV.ZG93bmxvYWR8WHg2T1RGMmRueDhNVFkyT1RnMk1qSTRObng4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA/burrill.patshull PDF link annotation
    • https://curtadoc.tv/wp-content/uploads/2022/12/nirerbu.pdfIn PDF document text
    • http://efekt-metal.pl/?p=1In PDF document text
    • https://azizeshop.com/wp-content/uploads/2022/12/Literary_Devices_In_The_Poem_Miracles_By_Walt_Whitman.pdfIn PDF document text
    • https://tribetotable.com/wp-content/uploads/2022/12/latchah.pdfIn PDF document text
    • https://www.wangfuchao.com/wp-content/uploads/2022/12/Prog12z_Programmer_V_167_EXCLUSIVE.pdfIn PDF document text
    • https://freecricprediction.com/wp-content/uploads/2022/12/rajashivchatrapatibookbybabasahebpurandarepdfdownload.pdfIn PDF document text
    • https://mentorus.pl/naukrani-ka-doodh-piya-hindi-pdf-sex-story-blumentopf-teamspeak/In PDF document text
    • https://eveningandmorningchildcareservices.com/wp-content/uploads/2022/12/CATIA_V5R21_Crack_JSOGROUPdllrar_INSTALL.pdfIn PDF document text
    • http://www.standardnews.in/wp-content/uploads/2022/12/aryaflli.pdfIn PDF document text
    • https://epochbazar.com/wp-content/uploads/2022/12/villu_tamil_movie_hd_downloads.pdfIn PDF document text
    • https://azizeshop.com/wp-content/uploads/2022/12/Literary_Devices_In_The_Poem_Miracles_By_In PDF document text
    • https://www.wangfuchao.com/wp-content/uploads/2022/12/Prog12z_Programmer_V_167_EXCLUIn PDF document text
    • https://freecricprediction.com/wp-content/uploads/2022/12/rajashivchatrapatibookbybabasahebpIn PDF document text
    • https://eveningandmorningchildcareservices.com/wp-content/uploads/2022/12/CATIA_V5R21_CraIn PDF document text
    • http://seachtop.com/enchants/?implemantation=overviewed.tmv0c3bvdcbqcm8grnvsbcbdcmfjayaymgtmv.zg93bmxvywr8whg2t1rgmmruedhnvfkyt1rnmk1qstrobng4twpvnu1iedhlrtbwsuzkdmntundjbvz6y3lcyldfmu1vbejesuzzeulgqkvsbda/burrill.patshullIn PDF document text
    • http://dejavu.sourceforge.netIn extracted file (stream_005_off00002e90.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (stream_005_off00002e90.bin)
🗂 Part of campaign: secureserver.net 1471 samples

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off00002e90.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2E90 20144 bytes
SHA-256: 7ad3ce2c22781aaabd3972801f203e4765093efdf89b5b38ccd3a715c7fdc74e
stream_009_off000092b6.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x92B6 119072 bytes
SHA-256: df221e87b81d1531cafdadb6c09a602e9f604d1baf0a17bbd350cbb83baa06f7
font_01_sfnt_off00006341.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6341 19964 bytes
SHA-256: 5154a7c8cf7a9b55c2f939ad6a4a8f8327cd6552b9f68a87c49d10dfc747eaa8