Malicious PDF — malware analysis report

Static analysis result for SHA-256 f2fede9c1dd69bf0…

MALICIOUS

PDF

111.5 KB Created: 2022-09-09 10:02:34 +00:00 Authoring application: reiglawr (via PDF Master 1.0.1) First seen: 2026-06-13
MD5: f9127cb203689d97c209a70c04fbdc64 SHA-1: eec96064ef7e9ad02b628ed4fc52879dc73405c2 SHA-256: f2fede9c1dd69bf0e5528cbb9952fa518672534d2b6524c300dddcb4154e783a
94 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0014

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://siteslocate.com/surya/calcholithic?/SEQgT25saW5lIFBsYXllciAoS29sbGltYWxhaSBTaW5nYW0gVGFtaWwgTW92aWUpSEQ/ZG93bmxvYWR8OFF0Tm1ReGVueDhNVFkyTWpZNE1ETTVNSHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA/gaffer/electrocute.lucia PDF link annotation
    • https://www.mycatchyphrases.com/powerstrip-3-90-build-736-crack-betterl/In PDF document text
    • https://srilankanguides.com/wp-content/uploads/2022/09/bunnmart.pdfIn PDF document text
    • https://holidaysbotswana.com/wp-content/uploads/2022/09/download_cisco_ip_communicator_8_6_free_236.pdfIn PDF document text
    • https://remcdbcrb.org/wp-content/uploads/2022/09/Download_PATCHED_Mastercam_X8_Full_Crack_64bit_Vs_32bit.pdfIn PDF document text
    • https://mydreamfinances.com/wp-content/uploads/2022/09/Radar_105_Homeopathic_Software_HOT_Crack_26l.pdfIn PDF document text
    • https://generalskills.org/%fr%In PDF document text
    • https://multiherramientas.mx/wp-content/uploads/2022/09/Loquendo_Text_To_Speech_754_Multilenguajerar_Download_Pc_UPD.pdfIn PDF document text
    • https://champlife.de/wp-content/uploads/2022/09/Antares_AVOX_Evo_VST_RTAS_v302_AiR_crack.pdfIn PDF document text
    • https://sugaringspb.ru/golden-eye-4-50-rar-hot/In PDF document text
    • https://pmeceu.com/wp-content/uploads/2022/09/Refprop_Matlab_Download_For_Windowsl.pdfIn PDF document text
    • http://modiransanjesh.ir/police-order-2002-in-urdu-pdf-free-download/In PDF document text
    • http://theartdistrictdirectory.org/wp-content/uploads/2022/09/Subtitle_Indonesia_Gladiators_Of_215_NEW.pdfIn PDF document text
    • https://nchscourant.com/wp-content/uploads/2022/09/Fable_3_Activation_Key_Keygen_NEWl.pdfIn PDF document text
    • http://lawcate.com/superman-2-dublado-torrent/In PDF document text
    • https://asu-bali.jp/wp-content/uploads/2022/09/lasdayj.pdfIn PDF document text
    • http://applebe.ru/2022/09/09/need-for-speed-undercover-problem-solution-by-v-rar-rar/In PDF document text
    • https://superyacht.me/advert/train-valley-2-activation-code-torrent/In PDF document text
    • https://alafdaljo.com/chirag-hd-movies-free-download-720p/In PDF document text
    • https://doctorcombine.com/wp-content/uploads/2022/09/ladsan.pdfIn PDF document text
    • https://dbsangola.com/wp-content/uploads/2022/09/farrhay.pdfIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text