Malicious PDF — malware analysis report

Static analysis result for SHA-256 09c42f24d3a8ff0b…

MALICIOUS

PDF

76.9 KB Created: 2021-04-06 00:42:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-04
MD5: 7517473e3f807476d1aadd5c71d73214 SHA-1: d180138d969df398b1d4ceb81a9b6c8bcff3d4d8 SHA-256: 09c42f24d3a8ff0be95bb279cc1da8ed419c94ef61395d5ac13e3b95a35ce5c6
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains numerous embedded URLs, with a primary one pointing to 'mezovuduw.ru', suggesting a phishing or malware distribution lure disguised as a lab answer key. The PDF's structure and the presence of many external links on disposable hosting further support its role as a malicious document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/wix?keyword=percent+composition+of+a+penny+lab+answers PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4450418/normal_603c857a9302c.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4451348/normal_5feb69e7827a4.pdfIn PDF document text
    • https://juwexulomo.weebly.com/uploads/1/3/4/3/134385858/9199527.pdfIn PDF document text
    • http://inmyshtangen.xyz/graphing_lines_using_x_and_y_intercepts_worksheet9m1vc.pdfIn PDF document text
    • http://differencecheats.net/contemplate_my_lifeqdjv1.pdfIn PDF document text
    • http://www19216801.site/80097062913mrf4e.pdfIn PDF document text
    • http://dvertsoff.ru/2005_honda_civic_si_hatchback_owners_manualwdgpy.pdfIn PDF document text
    • https://cdn.sqhk.co/guvawatuzax/ifkQihT/diy_dice_tray_ikea.pdfIn PDF document text
    • https://rapinawenag.weebly.com/uploads/1/3/0/9/130969945/pelopinunakag_regufedug_depepolil.pdfIn PDF document text
    • https://cdn.sqhk.co/taxodisilif/4jgS0na/19109766543.pdfIn PDF document text
    • https://cdn.sqhk.co/wudenedu/FWUgiRO/digestive_biscuits_brands_usa.pdfIn PDF document text
    • http://carbackseat.site/survival_game_jurassic_evolution_world_mod_apkv70mx.pdfIn PDF document text
    • http://legionmone.xyz/labirent_3_indir_trke_dublaj0atqt.pdfIn PDF document text
    • http://effektzhizni.ru/sony_playstation_vita_16gb_memory_cardeoazb.pdfIn PDF document text
    • https://cdn.sqhk.co/gofejenizew/bQnRmfk/57360851704.pdfIn PDF document text
    • https://cdn.sqhk.co/nemalerute/aQCifgi/door_kickers_2_task_force_north_apk.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4420743/normal_60344201d5822.pdfIn PDF document text
    • https://metidelesaweso.weebly.com/uploads/1/3/0/8/130813592/zoruronuvat_vutafedotapax.pdfIn PDF document text
    • http://timelessdecorum.com/kotisififedadeluweleeh5i8.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/861e9cfd-127f-442c-bcc9-330392448166/94109310231.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/364d7858-4f4b-4b29-b104-b358839a6780/troy_bilt_tb20cs_spark_plug.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fc8fd94c-da14-4238-9305-8fe46e88a83f/zubow.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e185.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE185 2900 bytes
SHA-256: 68d094faf81d2ea9f62e68ee4e789e40b6192f27e323b9e50c58fbaa8f881837
font_01_sfnt_off0000ebc8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEBC8 5496 bytes
SHA-256: f88732242905473f082b35e372fa7b4784db097f9c7395bcac40f4d1033e7092
font_02_sfnt_off0000fe79.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFE79 11540 bytes
SHA-256: 2eb1a0e8bf08cff061f991f4320cc43221d04a0c5feb5e9b93e953c22b56e925