Malicious PDF — malware analysis report

Static analysis result for SHA-256 ab74fc43e0c8bea6…

MALICIOUS

PDF

128.5 KB Authoring application: Skia/PDF m150 Google Docs Renderer First seen: 2026-05-19
MD5: 6ce9e3d8ca9a0dd1d1d22ef5c12930cd SHA-1: 393f531f4a78701cc7b32fb8f437e17bc3402e68 SHA-256: ab74fc43e0c8bea68f10760862a6bbbb56e02ff1a3e99be18effcf9dfae21e92
62 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0001

Heuristics 2

  • Invisible/repeated PDF links deliver payload file critical PDF_REPEATED_PAYLOAD_LINK_LURE
    PDF uses invisible link annotations and points to a direct payload download. Repeated invisible links or lure-like payload names such as document/unlock/verify archives match malware-delivery PDF carriers where the page is only a prompt and the real payload is fetched from the linked URL.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cms.volaris.com/es/informacion-util/antes-de-tu-vuelo/cambia-tu-vuelo/?utm_source=chatgpt.com In PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_013_off000175c5.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x175C5 145348 bytes
SHA-256: 8b7801f9414ba7ebd3223fd7a6af8dd3cd32933c2ff011024080a6a0c35dd2b2
font_00_sfnt_off0000fa32.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFA32 133588 bytes
SHA-256: 3485e6b646aa1467ef65fa84f79e6421f9c2fc09868ea42c69237deecea80c2b
font_01_sfnt_off00016047.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16047 173616 bytes
SHA-256: b5116810e665cae342f4b6ba3618ee25b5246561744ea60946186a637702f357
font_02_sfnt_off00016c85.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16C85 26852 bytes
SHA-256: c2bc228dab6749281a37e75b5ca855eb7876eef8560100db336ac9694defe3ac