Malicious PDF — malware analysis report

Static analysis result for SHA-256 03f610169885c75c…

MALICIOUS

PDF

69.5 KB Created: 2020-12-28 14:30:26 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-05
MD5: f3de53a8c4a9533801419c6803577800 SHA-1: 70e3ff5ab38f0e5e222b35f6f85e63d17aa88bbc SHA-256: 03f610169885c75c442529f87b7105849cf448b38584768c24aefd168b52023b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that leads to a page offering a hack for 'Sausage wars.io', strongly suggesting a phishing or social engineering lure. ClamAV detection and ML classification confirm its malicious nature. The document body, though heavily obfuscated, contains references to the game and the wkhtmltopdf tool, further supporting the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/strik?utm_term=sausage+wars.+io+hack+apk PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4477916/normal_5fe63ffb3fd17.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369629/normal_5f8b03d258f12.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4383321/normal_5f9aa71fa6de2.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4484143/normal_5fb2ac48211b8.pdfIn PDF document text
    • https://burufazifefep.weebly.com/uploads/1/3/4/5/134584298/kumog-zojubi-vakomikufer-pivatubazuxu.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4380210/normal_5f9a8b5bc8623.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4450042/normal_5fa1e5b5c15c8.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/wikurixobelu/taxenuzimoza.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ce4b8a65-1402-423f-bb5b-dcd7a1245f72/biology_levels_of_organization_worksheet.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/705cb388-117f-46fc-b57d-f780a5f37825/czardas_violin_solo_sheet_music.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cc0b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCC0B 5456 bytes
SHA-256: a1ad2ad59ba26a190c9002b33deffc0f500948fb73a5c2dc77af08902788be55
font_01_sfnt_off0000deab.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDEAB 12972 bytes
SHA-256: cf5c3a848fec0a17cd2c6796f85b03e3fb01735e90be0e4edec8bd68bb3b89b2