Malicious PDF — malware analysis report

Static analysis result for SHA-256 ad14bbd79c2a0315…

MALICIOUS

PDF

34.0 KB Created: 2024-07-29 08:42:01 +02:00 Authoring application: 376377000l000a000s000c000h000e000r (via GPL Ghostscript 10.03.0) First seen: 2026-05-02
MD5: 8900e7b6b1318023fb8b086f65ce83da SHA-1: d9472b3a1d89a01f09462f09b0aef7667644c56a SHA-256: ad14bbd79c2a0315459bd17361bb72c8a37ae737627722c6dd1d5e6a69d5f1e8
304 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0182

Heuristics 9

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Cracked-software lure uses shortlink/download gateway critical PDF_CRACKED_SOFTWARE_SHORTLINK_LURE
    PDF visible text advertises a crack, serial number, archive, or pirated-software download and pairs it with a shortlink or encoded download gateway. This is a high-confidence social-engineering carrier for unwanted software or droppers; the PDF itself is not a parser exploit.
  • Cracked-software lure uses download-gateway redirectors high PDF_CRACKED_SOFTWARE_REDIRECTOR_LINK_FARM
    PDF contains multiple cracked-software/keygen/serial-key lure links together with long encoded download-gateway URLs or known crack-download redirector hosts. This is stronger than generic piracy vocabulary: the document is an SEO lure that funnels users through redirect/download infrastructure commonly used for adware, unwanted software, or droppers.
  • PDF links to a cracked-software download doorway (base64-obfuscated) high PDF_CRACKED_SOFTWARE_DOWNLOAD_DOORWAY
    PDF's embedded link hides a pirated-software title as a base64 blob inside the URL path/query (and/or carries the ``download|`` doorway-template marker), rather than in visible text. This is a TCPDF-generated SEO doorway that ranks for software-piracy searches and funnels users to fake 'crack/keygen' download pages distributing adware, potentially-unwanted programs, or droppers. The base64 encoding is deliberate obfuscation to evade plaintext lure rules; the PDF itself carries no parser exploit — the risk is the linked crack-download destination.
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xtraserp.com/aster/federalized/ringworms.gossage?../ZG93bmxvYWR8elgwTlhScllYeDhNVFkzTURnek5ETXdPWHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA/jewelries/ringlets.Q2xpcFBhdGgQ2x PDF link annotation
    • https://www.infoslovakia.sk/wp-content/uploads/2022/12/IPlaylist-Crack-License-Code-Keygen-Free.pdfIn PDF document text
    • https://www.texaslocalguide.com/wp-content/uploads/2022/12/Liyana-Mahaththaya-For-Word-Crack-Activation-Latest2022.pdfIn PDF document text
    • https://earthoceanandairtravel.com/wp-content/uploads/2022/12/malugol.pdfIn PDF document text
    • https://arlingtonliquorpackagestore.com/wp-content/uploads/2022/12/Trend-Micro-WorryFree-Business-Security-Crack-Free-Download.pdfIn PDF document text
    • https://lifandihefdir.is/wp-content/uploads/2022/12/chaalay.pdfIn PDF document text
    • https://arabamericanbusinesscommunity.org/wp-content/uploads/2022/12/WheelEncoderGenerator.pdfIn PDF document text
    • https://bdmentors.org/2022/12/12/portable-free-download-manager-lite-crack-license-key-free-latest/In PDF document text
    • https://bmpads.com/2022/12/12/startpage-privacy-protection-for-chrome-crack-for-pc-updated-2022/In PDF document text
    • https://newmarketbusiness.com/wp-content/uploads/Copenhagen-OS-Emulation-Suite.pdfIn PDF document text
    • https://weycup.org/wp-content/uploads/2022/12/bentzaka.pdfIn PDF document text
    • https://www.infoslovakia.sk/wp-content/uploads/2022/12/IPlaylist-Crack-License-Code-Keygen-FreIn PDF document text
    • https://www.texaslocalguide.com/wp-content/uploads/2022/12/Liyana-Mahaththaya-For-Word-CracIn PDF document text
    • https://arlingtonliquorpackagestore.com/wp-content/uploads/2022/12/Trend-Micro-WorryFree-BusiIn PDF document text
    • https://arabamericanbusinesscommunity.org/wp-content/uploads/2022/12/WheelEncoderGeneratoIn PDF document text
    • https://bdmentors.org/2022/12/12/portable-free-download-manager-lite-crack-license-key-free-lateIn PDF document text
    • https://bmpads.com/2022/12/12/startpage-privacy-protection-for-chrome-crack-for-pc-updated-202In PDF document text
    • http://xtraserp.com/aster/federalized/ringworms.gossage?../zg93bmxvywr8elgwtlhscllyedhnvfkzturnek5etxdpwhg4twpvnu1iedhlrtbwsuzkdmntundjbvz6y3lcyldfmu1vbejesuzzeulgqkvsbda/jewelries/ringlets.q2xpcfbhdggq2xIn PDF document text
    • https://arlingtonliquorpackagestore.com/wp-content/uploads/2022/12/trend-micro-worryfree-business-security-crack-free-download.pdfIn PDF document text
    • https://magic.ly/bracirZreawoIn PDF document text
    • https://techplanet.today/post/8dio-requiem-professional-torrenIn PDF document text
    • https://techplanet.today/post/wish-you-were-here-pink-floyd-top-free-mp3-download-beeIn PDF document text
    • https://techplanet.today/post/hd-online-player-golden-item-girl-full-movie-online-7-newIn PDF document text
    • https://reallygoodemails.com/chrontayfanyoIn PDF document text
    • https://reallygoodemails.com/atparvfraceIn PDF document text
    • https://reallygoodemails.com/cruspo0caniIn PDF document text
    • https://techplanet.today/post/apulsoft-apqualizr-223In PDF document text
    • https://techplanet.today/post/mythicsoft-filelocator-pro-752092-multilang-portable-free-download-topIn PDF document text
    • https://techplanet.today/post/mythicsoft-filelocator-pro-752092-multilang-portable-free-download-tIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/iX/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004f53.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4F53 8884 bytes
SHA-256: 07cf560d76ba0a01d8de7739d9eb42aaa655994ec879d6fec3b7a17e5e4202c1
font_01_sfnt_off000068d1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x68D1 6552 bytes
SHA-256: e7ea885c4d19504429369668d1b32d1c75798082077cbfff53dd956d16dd5c9b