Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0c60204eaaad5ac…

MALICIOUS

PDF

111.8 KB Created: 2022-09-11 11:57:03 +00:00 Authoring application: ellnels (via PDF Master 1.0.1) First seen: 2026-05-02
MD5: 5a9f7c0a88b73d52866418417c1985b2 SHA-1: f12ccaebe271d790a35a0710124ea0102a760cb1 SHA-256: c0c60204eaaad5ac172c45d65d0d7631ee65f99e7c620ba7944a3a66ba0227c6
264 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0012

Heuristics 8

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Cracked-software lure uses shortlink/download gateway critical PDF_CRACKED_SOFTWARE_SHORTLINK_LURE
    PDF visible text advertises a crack, serial number, archive, or pirated-software download and pairs it with a shortlink or encoded download gateway. This is a high-confidence social-engineering carrier for unwanted software or droppers; the PDF itself is not a parser exploit.
  • Cracked-software lure uses download-gateway redirectors high PDF_CRACKED_SOFTWARE_REDIRECTOR_LINK_FARM
    PDF contains multiple cracked-software/keygen/serial-key lure links together with long encoded download-gateway URLs or known crack-download redirector hosts. This is stronger than generic piracy vocabulary: the document is an SEO lure that funnels users through redirect/download infrastructure commonly used for adware, unwanted software, or droppers.
  • PDF links to a cracked-software download doorway (base64-obfuscated) high PDF_CRACKED_SOFTWARE_DOWNLOAD_DOORWAY
    PDF's embedded link hides a pirated-software title as a base64 blob inside the URL path/query (and/or carries the ``download|`` doorway-template marker), rather than in visible text. This is a TCPDF-generated SEO doorway that ranks for software-piracy searches and funnels users to fake 'crack/keygen' download pages distributing adware, potentially-unwanted programs, or droppers. The base64 encoding is deliberate obfuscation to evade plaintext lure rules; the PDF itself carries no parser exploit — the risk is the linked crack-download destination.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://find24hs.com/geocities/decongest.fmcsa?/jbod/ZG93bmxvYWR8ZnIzZURselkzeDhNVFkyTWpZNE1ETTVNSHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA/UEFUQ0hFRCBWYW5EeWtlIFNlY3VyZUNSVCBBbmQgU2VjdXJlRlggOC41LjIgQnVpbGQgMTc5OSBNZWRpY2luZVtCYWJ1UAUEF PDF link annotation
    • https://brutalrecords.com/coming-soon/In PDF document text
    • https://hiepsibaotap.com/wp-content/uploads/2022/09/Neighbours_Movie_Download_BEST_In_Bluray_Torrent.pdfIn PDF document text
    • https://deccan-dental.com/patchhitman-absolution-update-v-1-0-446-0-link/In PDF document text
    • https://parsiangroup.ca/2022/09/slysoft-clonedvd-v2-9-3-3-keygen-crack-2021/In PDF document text
    • https://koeglvertrieb.de/wp-content/uploads/2022/09/gilpry.pdfIn PDF document text
    • https://seo-gurus.net/chichewabibleverified-download/In PDF document text
    • http://leasevoordeel.be/wp-content/uploads/2022/09/Radiant_Dicom_Viewer_NEW_Cracked_64l.pdfIn PDF document text
    • https://www.dandrea.com.br/advert/nch-debut-video-capture-software-pro-10-2-beta-crack-download-fixed/In PDF document text
    • https://mocambique.online/wp-content/uploads/2022/09/nateve.pdfIn PDF document text
    • https://mevoydecasa.es/album-sixty-miles-the-first-mile-cbr320kbps-link/In PDF document text
    • https://golden-hands.co/clash-of-clans-pc-game-download-torrent-downloadl-new/In PDF document text
    • http://bariatric-club.net/?p=60963In PDF document text
    • https://www.faceauxdragons.com/advert/principles-of-mathematics-9-exercise-and-homework-book/In PDF document text
    • https://vv411.com/advert/titanic-3d-verified-full-movie-in-hindi-hd-1080p-2012-moviesl/In PDF document text
    • https://www.dominionphone.com/thottal-poo-malarum-full-full-movie-download/In PDF document text
    • https://www.mozideals.com/advert/nitro-pdf-professional-7-0-2-8-x64-incl-link-crack-patch/In PDF document text
    • http://modiransanjesh.ir/advanced-uninstaller-pro-7-2-serial-key-__hot__/In PDF document text
    • https://serkit.ru/wp-content/uploads/2022/09/Povestiri_Istorice_Dumitru_Almas_Pdf_Download_VERIFIED_.pdfIn PDF document text
    • http://cipheadquarters.com/?p=57800In PDF document text
    • https://ofsnl.nl/wp-content/uploads/2022/09/wilhleti.pdfIn PDF document text
    • http://find24hs.com/geocities/decongest.fmcsa?/jbod/zg93bmxvywr8znizzurselkzedhnvfkytwpzne1ettvnshg4twpvnu1iedhlrtbwsuzkdmntundjbvz6y3lcyldfmu1vbejesuzzeulgqkvsbda/uefuq0hfrcbwyw5eewtlifnly3vyzunsvcbbbmqgu2vjdxjlrlggoc41ljigqnvpbgqgmtc5osbnzwrpy2luzvtcywj1uauefIn PDF document text
    • http://leasevoordeel.be/wp-content/uploads/2022/09/radiant_dicom_viewer_new_cracked_64l.pdfIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text
🗂 Part of campaign: secureserver.net 1471 samples

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000012b9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12B9 84508 bytes
SHA-256: 2b7ba551bea82cc3307397981c1dbeb1b78486f95f2eb14e5e58d4e1b24edb0c
font_01_sfnt_off00009aa5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9AA5 83036 bytes
SHA-256: 6d13e73e85a502a13969f6a5eaecd0b275a0868c045f80b7d64ed55d70678261