Malicious PDF — malware analysis report

Static analysis result for SHA-256 f2faa9b240c503f6…

MALICIOUS

PDF

113.1 KB Created: 2022-07-24 22:14:29 +00:00 Authoring application: phiunex (via PDF Master 1.0.1) First seen: 2026-06-13
MD5: 74677ef74de3d4ad4d097580b553b949 SHA-1: aa64f86166ea51d103375aad55721b4b25e686a3 SHA-256: f2faa9b240c503f600edd5e326bff34af63da65000b12ac018b0beb08d083590
94 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0014

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dormister.com/devaluation/mazzone/palms/QXBleHNxbExvZ0NyYWNrT3JLZXlPckFjdGl2YXRpb25LZXkxNQQXB.rustling?parom/perspicuity/ZG93bmxvYWR8ODR6YUhkNGZId3hOalU0TWpFNE9UZzFmSHd5TlRrd2ZId29UU2tnVjI5eVpIQnlaWE56SUZ0WVRVeFNVRU1nVmpJZ1VFUkdYUQ.sportsline PDF link annotation
    • https://atiqxshop.nl/wp-content/uploads/2022/07/janswero.pdfIn PDF document text
    • https://www.apokoronews.gr/advert/chamandurgastutiinhindipdf11-upd/In PDF document text
    • https://r-posts.com/wp-content/uploads/2022/07/Cube_Iq_40_Full_Crack_TOP.pdfIn PDF document text
    • https://missionmieuxetre.com/2022/07/24/patched-siemens-vas-5052-recovery-dvd/In PDF document text
    • https://www.drbonesonline.com/wp-content/uploads/2022/07/pauhas.pdfIn PDF document text
    • https://buyliveme.com/wp-content/uploads/2022/07/Adobe_XD_CC_2018_v4013_Crack_Working_Exclusive_Serial_Key_ke.pdfIn PDF document text
    • http://www.hacibektasdernegi.com/wp-content/uploads/olywar.pdfIn PDF document text
    • http://www.publicpoetry.net/2022/07/strawberry-shortcake-card-maker-dress-up-hack-full/In PDF document text
    • https://unimedbeauty.com/wp-content/uploads/2022/07/Kore_Player_Key_Generator_2_HOT.pdfIn PDF document text
    • https://staging.sonicscoop.com/advert/__top__-crack-para-neodata-2014-126/In PDF document text
    • https://metamorfosisdelempresario.com/wp-content/uploads/2022/07/Medio_Ambiente_Y_Desarrollo_Sostenible_Paolo_Bifani_Pdf_53.pdfIn PDF document text
    • https://ramchandars.com/wp-content/uploads/2022/07/mardeav-1.pdfIn PDF document text
    • http://deepcarepm.com/wp-content/uploads/2022/07/Free_Download_Hysys_32_Crack.pdfIn PDF document text
    • http://www.hacibektasdernegi.com/wp-content/uploads/Bosch_Esi_Tronic_2012_Q4_Keygen_28_LINK.pdfIn PDF document text
    • https://kimgbg.se/wp-content/uploads/2022/07/Philips_Wifi_Media_Connect_Extra_Quality.pdfIn PDF document text
    • https://www.cerezhane.com/wp-content/uploads/2022/07/downloadkitabalfiqhalislamiwaadillatuhupdfviewer.pdfIn PDF document text
    • https://bucatarim.com/wii-beat-the-beat-rhythm-paradise-pal-multi-5-wbfs-top/In PDF document text
    • https://www.larpy.cz/files/phigion.pdfIn PDF document text
    • http://hshapparel.com/wajibat-e-namaz-urdu-pdf-14-ausdrucken-bannerwer-free/In PDF document text
    • http://executivenavi.com/wp-content/uploads/2022/07/widi_41_pro_keygen.pdfIn PDF document text
    • http://deepcarepm.com/wp-content/uploads/2022/07/free_download_hysys_32_crack.pdfIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text