Malicious PDF — malware analysis report

Static analysis result for SHA-256 af2e1143ae898f96…

MALICIOUS

PDF

120.4 KB Created: 2022-07-26 07:22:54 +00:00 Authoring application: grajew (via PDF Master 1.0.1) First seen: 2026-06-21
MD5: 61bd180b5eb96a226cf4710edc2aef25 SHA-1: bd4fb123193d25c54b335a84cfb008fecc40ce3e SHA-256: af2e1143ae898f96b42f19252309f8aaafb5e38d3562a0a9f3472956bcfcb121
64 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0010

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://blogbasters.com/aquila/finds/morgellons.lynne?utilising.eGZvcmNlIGtleWdlbiBBbGlhcyBTcGVlZEZvcm0gMjAxOCBvbmxpbmUeGZ=ZG93bmxvYWR8c1gwTVRKdmNuaDhmREUyTlRneU1UZzVPRFY4ZkRJMU9UQjhmQ2hOS1NCWGIzSmtjSEpsYzNNZ1cxaE5URkpRUXlCV01pQlFSRVpk PDF link annotation
    • https://it-sbo.com/wp-content/uploads/2022/07/jourber.pdfIn PDF document text
    • https://humboldtgreenjobs.com/wp-content/uploads/2022/07/CyberLink_PowerDirector_Ultimate_17631250_Patch.pdfIn PDF document text
    • https://boldwasborn.com/cbt-nuggets-microsoft-windows-server-2012-70-412-verified/In PDF document text
    • http://it-labx.ru/?p=97252In PDF document text
    • http://awaazsachki.com/?p=55950In PDF document text
    • http://weedcottage.online/?p=111835In PDF document text
    • https://comoemagrecerrapidoebem.com/?p=34259In PDF document text
    • https://ryansellsflorida.com/wp-content/uploads/2022/07/kaflat.pdfIn PDF document text
    • https://heronetworktv.com/wp-content/uploads/2022/07/SamsungSECCSD_LH43STAR_LTP21bin_NEW.pdfIn PDF document text
    • https://vamaveche2mai.ro/wp-content/uploads/2022/07/color_screen_calendar_model_8190_zip.pdfIn PDF document text
    • https://evol.ai/dgex/index.php/advert/cheetah-rock-and-roll-women-cd-flac-2013-wre/In PDF document text
    • https://www.bg-frohheim.ch/bruederhofweg/advert/hd-online-player-thandavam-tamil-full-movie-dvdrip-free-30-__hot__/In PDF document text
    • http://mysquare.in/?p=In PDF document text
    • http://www.giffa.ru/who/i-am-alive-serial-keyl/In PDF document text
    • https://autoentrespasos.com/advert/top-crack-adobe-premiere-pro-cc-2018-12-0-0-224-portable-x64/In PDF document text
    • http://pepsistars.com/it-is-not-found-any-file-specified-for-isarcextract/In PDF document text
    • https://teenmemorywall.com/zara-dholki-bajao-goriyo-adnan-sami-mp3-free-download-link/In PDF document text
    • https://iled.in/wp-content/uploads/2022/07/Toontrackezmix2keygentorrent_PORTABLE.pdfIn PDF document text
    • https://alfagomeopatia.ru/wp-content/uploads/oceaharb.pdfIn PDF document text
    • https://www.synergytherm.com/wp-content/uploads/2022/07/henmang.pdfIn PDF document text
    • https://humboldtgreenjobs.com/wp-content/uploads/2022/07/CyberLink_PoweIn PDF document text
    • https://boldwasborn.com/cbt-nuggets-microsoft-windows-In PDF document text
    • https://heronetworktv.com/wp-In PDF document text
    • https://vamaveche2mai.ro/wp-In PDF document text
    • https://evol.ai/dgex/index.php/advert/cheetah-rock-and-roll-women-cd-In PDF document text
    • https://www.bg-frohheim.ch/bruederhofweg/advert/hd-online-player-In PDF document text
    • https://autoentrespasos.com/advert/top-crack-adobe-premiere-pro-In PDF document text
    • https://teenmemorywall.com/zara-dholki-bajao-goriyo-adnan-sami-mp3-free-In PDF document text
    • https://iled.in/wp-In PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text