Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8a75a4c450e1871…

MALICIOUS

PDF

136.0 KB Created: 2022-09-12 11:00:05 +00:00 Authoring application: gilque (via PDF Master 1.0.1) First seen: 2026-05-05
MD5: 7aef23b2d6ccb7613b5d525073d55104 SHA-1: 92f6dfe5d08aafd842039844179f8b558782d2c2 SHA-256: e8a75a4c450e187196539a5998e43a09709f030a5361749187d819801532412b
249 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0007

Heuristics 8

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Cracked-software lure uses shortlink/download gateway critical PDF_CRACKED_SOFTWARE_SHORTLINK_LURE
    PDF visible text advertises a crack, serial number, archive, or pirated-software download and pairs it with a shortlink or encoded download gateway. This is a high-confidence social-engineering carrier for unwanted software or droppers; the PDF itself is not a parser exploit.
  • Cracked-software lure uses download-gateway redirectors high PDF_CRACKED_SOFTWARE_REDIRECTOR_LINK_FARM
    PDF contains multiple cracked-software/keygen/serial-key lure links together with long encoded download-gateway URLs or known crack-download redirector hosts. This is stronger than generic piracy vocabulary: the document is an SEO lure that funnels users through redirect/download infrastructure commonly used for adware, unwanted software, or droppers.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • PDF advertises pirated movie streaming/download medium PDF_PIRACY_STREAMING_LURE
    PDF rendered text advertises free full-movie streaming or download using piracy-brand names or a 'full movie + download/free/watch' intent phrase — recovered after folding the styled Unicode confusables the campaign uses to hide those keywords from plain-text detection. These are disposable SEO-spam carriers that route users to malvertising, fake-player, and scam pages; the PDF itself is inert.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://awarefinance.com/VGVyYUNvcHlQcm80Mk11bHRpbGluZ3VhbEluY2xDcmFja1BvcnRhYmxlU2VyaWFsS2V5VGV/icelandair.casses.liked/istorage?kilpsan=ZG93bmxvYWR8Qlk2TVRoNGFETjhmREUyTmpJMk9EQXpPVEI4ZkRJMU9UQjhmQ2hOS1NCWGIzSmtjSEpsYzNNZ1cxaE5URkpRUXlCV01pQlFSRVpk PDF link annotation
    • https://serippyshop.com/black-friday-full-upd-movie-hindi-in-mp4-free-download/In PDF document text
    • https://ayusya.in/alcatal-4034x-dead-recovery-firmware-flash-file-mt6580/In PDF document text
    • http://www.fuertebazar.com/wp-content/uploads/2022/09/SolidWorks2018Activator_free_download.pdfIn PDF document text
    • https://sourav.info/wp-content/uploads/2022/09/Wpematico_Pro_Nulled_And_Void_PATCHED.pdfIn PDF document text
    • https://verycheapcars.co.zw/advert/download-solution-manual-to-options-futures-and-other-derivatives-added-patched/In PDF document text
    • https://xn--80aagyardii6h.xn--p1ai/patched-bitcoin-generator-v-4-5/In PDF document text
    • http://implicitbooks.com/advert/how-to-play-assassins-creed-unity-online-cracked-portable/In PDF document text
    • https://parisine.com/wp-content/uploads/2022/09/zehapow.pdfIn PDF document text
    • https://www.riobrasilword.com/2022/09/12/ju-on-the-grudge-pc-game-download-portable-free/In PDF document text
    • https://macausian.com/wp-content/uploads/2022/09/Edi_Notepad_Professional_Serial_98.pdfIn PDF document text
    • http://gametimereviews.com/?p=67788In PDF document text
    • http://babussalam.id/?p=48629In PDF document text
    • http://palladium.bg/wp-content/uploads/2022/09/Any_DVD_Converter_Professional_634_Multilingual.pdfIn PDF document text
    • https://cambodiaonlinemarket.com/resolume-arena-41-3-full-link-crack/In PDF document text
    • https://inmobiliaria-soluciones-juridicas.com/2022/09/securecrt-73-license-key-serial-numberIn PDF document text
    • http://www.studiofratini.com/kaama-sutra-sinhala-pdf/In PDF document text
    • https://parsiangroup.ca/2022/09/agents-of-shield-season-1-download-free-link/In PDF document text
    • https://kalapor.com/full-mitek-20-20-engineering-new/In PDF document text
    • https://koi-rausch.de/wp-content/uploads/derbel.pdfIn PDF document text
    • https://ibipti.com/reallusion-crazytalk-animator-v3-12-1719-1-pipeline-full-crack-utorrent/In PDF document text
    • http://www.fuertebazar.com/wp-In PDF document text
    • https://verycheapcars.co.zw/advert/download-solution-manual-to-options-futures-and-other-In PDF document text
    • http://palladium.bg/wp-In PDF document text
    • http://awarefinance.com/vgvyyunvchlqcm80mk11bhrpbgluz3vhbeluy2xdcmfja1bvcnrhymxlu2vyawfss2v5vgv/icelandair.casses.liked/istorage?kilpsan=zg93bmxvywr8qlk2tvrongfetjhmreuytmpjmk9eqxppvei4zkrjmu9uqjhmq2hos1ncwgizsmtjsepsyznnz1cxae5urkpruxlcv01pqlfsrvpkIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text
🗂 Part of campaign: secureserver.net 1471 samples

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000152c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x152C 84508 bytes
SHA-256: 2b7ba551bea82cc3307397981c1dbeb1b78486f95f2eb14e5e58d4e1b24edb0c
font_01_sfnt_off00009d18.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9D18 83036 bytes
SHA-256: 6d13e73e85a502a13969f6a5eaecd0b275a0868c045f80b7d64ed55d70678261