Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa8e3ccbc4cb6483…

MALICIOUS

PDF

129.8 KB Created: 2022-07-05 07:04:20 +00:00 Authoring application: volichi (via PDF Master 1.0.1) First seen: 2026-06-06
MD5: cc730829d4329087d3fda910ab9471b8 SHA-1: cb677a43ae019ae2406917498566282972923be1 SHA-256: aa8e3ccbc4cb6483a6b2c66dedc671c4a8fbc5ac859e19064a0170dd7e527cc8
94 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0006

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lehmanbrotherbankruptcy.com/angioplasties/burin/moshe?ZG93bmxvYWR8eWowT1RWbVozeDhNVFkxTmprNE1UVXdOSHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA.mcmillan=preparers&QWRvYmUgUGhvdG9zaG9wIDIwMjIgKFZlcnNpb24gMjMuNC4xKQQWR=nokialand PDF link annotation
    • https://aqueous-peak-42580.herokuapp.com/yelapilg.pdfIn PDF document text
    • https://digitallibations.com/wp-content/uploads/2022/07/Photoshop_2022_.pdfIn PDF document text
    • http://jaxskateclub.org/wp-content/uploads/2022/07/Adobe_Photoshop_2020_version_21_Free.pdfIn PDF document text
    • https://quiet-refuge-44787.herokuapp.com/Adobe_Photoshop_2020.pdfIn PDF document text
    • https://eat-now.no/wp-content/uploads/2022/07/sylver.pdfIn PDF document text
    • https://drogadoboga.org/wp-content/uploads/2022/07/xanvyvi.pdfIn PDF document text
    • https://protected-forest-58330.herokuapp.com/Adobe_Photoshop_2021_Version_2243.pdfIn PDF document text
    • https://ldssystems.com/wp-content/uploads/marualt.pdfIn PDF document text
    • https://nameless-retreat-98060.herokuapp.com/breecomp.pdfIn PDF document text
    • https://heidylu.com/wp-content/uploads/2022/07/Adobe_Photoshop_2021.pdfIn PDF document text
    • http://seti.sg/wp-content/uploads/2022/07/Adobe_Photoshop_2022_Version_231.pdfIn PDF document text
    • https://www.urban-texture.it/wp-content/uploads/Adobe_Photoshop_CC.pdfIn PDF document text
    • https://www.forexwages.com/wp-content/uploads/2022/07/Adobe_Photoshop_CC_2015_version_17.pdfIn PDF document text
    • https://emsalat.ru/wp-content/uploads/2022/07/Photoshop_2021_Version_2231.pdfIn PDF document text
    • https://someuae.com/wp-content/uploads/2022/07/Adobe_Photoshop_keygen_only__Full_Version_Latest.pdfIn PDF document text
    • https://agile-forest-93611.herokuapp.com/Adobe_Photoshop_2021_Version_2201.pdfIn PDF document text
    • https://secret-fortress-08741.herokuapp.com/samabear.pdfIn PDF document text
    • https://awazpost.com/wp-content/uploads/2022/07/Photoshop_2021_Version_223_full_license__With_Full_Keygen.pdfIn PDF document text
    • https://cupcommunity.com/wp-content/uploads/2022/07/Photoshop_2021_Version_2242.pdfIn PDF document text
    • https://discoverlosgatos.com/wp-content/uploads/2022/07/Adobe_Photoshop_eXpress.pdfIn PDF document text
    • https://raguil2018.wixsite.com/quiquesaris/post/adobe-photoshop-2021-version-22-4-3-crack-serial-number-download-for-pc-march-2022In PDF document text
    • https://transfer8815.wixsite.com/enflucisfe/post/photoshop-cs5-crack-patch-download-32-64bitIn PDF document text
    • https://trello.com/c/lWYZAX8J/43-adobe-photoshop-2021-version-2251-crack-with-serial-number-activation-free-pc-windowsIn PDF document text
    • https://trello.com/c/4pX56lP6/43-adobe-photoshop-cc-2019-serial-number-freeIn PDF document text
    • http://conftila.yolasite.com/resources/Photoshop-2022-Version-2302-With-License-Code-Free-PCWindows.pdfIn PDF document text
    • https://trello.com/c/RbFE6ofa/66-adobe-photoshop-cc-2015-version-16-key-generator-free-registration-code-for-pc-updated-2022In PDF document text
    • http://fidyspnas.yolasite.com/resources/Adobe-Photoshop-2021-Version-2242-Crack-File-Only-.pdfIn PDF document text
    • http://suppcarzy.yolasite.com/resources/Photoshop-2022-Version-2301-Keygen-Full-Version-Download-3264bit.pdfIn PDF document text
    • https://trello.com/c/XlOS6WMB/115-adobe-photoshop-2021-version-225-keygen-crack-serial-key-serial-key-downloadIn PDF document text
    • https://wakelet.com/wake/3Yd1gYNZg6-rE5Stx_4lRIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text
    • http://conftila.yolasite.com/resources/photoshop-2022-version-2302-with-license-code-free-pcwindows.pdfIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002653.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2653 84508 bytes
SHA-256: 2b7ba551bea82cc3307397981c1dbeb1b78486f95f2eb14e5e58d4e1b24edb0c
font_01_sfnt_off0000ae3f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAE3F 83036 bytes
SHA-256: 6d13e73e85a502a13969f6a5eaecd0b275a0868c045f80b7d64ed55d70678261