Malicious PDF — malware analysis report

Static analysis result for SHA-256 184f1cf19674b391…

MALICIOUS

PDF

80.0 KB Created: 2021-03-28 11:55:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-04
MD5: 47e462a0c9636719b4861f61a3a2629a SHA-1: dcd9dc894cedf7fa8c2a96b5604a64a09f141f25 SHA-256: 184f1cf19674b39140c47ebe91441e10f23d6c29ac464d2c30b150d3f2ab5d7d
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains heuristics indicating it is a phishing lure, specifically using a 'free-download phishing' theme. It redirects to the URL https://xezojetit.ru/wix?keyword=chms+computer+lab+links, which is likely a phishing page. The ML classifier and ClamAV detection strongly support its malicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/wix?keyword=chms+computer+lab+links PDF link annotation
    • https://s3.amazonaws.com/tupofelasujewas/44420785795.pdfIn PDF document text
    • https://s3.amazonaws.com/pajukovuxetu/rofibexogadagu.pdfIn PDF document text
    • https://s3.amazonaws.com/vufuzewasi/good_morning_beautiful_whatsapp_status_video.pdfIn PDF document text
    • https://s3.amazonaws.com/widuxade/27384274593.pdfIn PDF document text
    • https://s3.amazonaws.com/jemisajoda/medudimigukemopo.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4383797/normal_60201966c8a39.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4450141/normal_605c86407c750.pdfIn PDF document text
    • https://s3.amazonaws.com/nigimul/62661529843.pdfIn PDF document text
    • http://bitsracing.net/mechanical_engineer_role_in_construction_sitepxdo6.pdfIn PDF document text
    • http://haustova.com/area_and_perimeter_anchor_chartuopc9.pdfIn PDF document text
    • https://s3.amazonaws.com/xutomoxu/dka_management_guidelines_sri_lanka.pdfIn PDF document text
    • https://s3.amazonaws.com/pozokimepe/an_introduction_to_language_10th_edition_answer.pdfIn PDF document text
    • https://s3.amazonaws.com/lizuseguwix/wordpress_blog_tutorial_2020.pdfIn PDF document text
    • http://hookup154.online/samujagivudepap1pssj.pdfIn PDF document text
    • http://avbox.org/kuvurelelaxegav0jbq.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4382189/normal_604ceba5c553f.pdfIn PDF document text
    • https://s3.amazonaws.com/timeziso/biludefuf.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4490121/normal_600faa1a77278.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4491159/normal_5fcb3769b88a7.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4470029/normal_5fddbc83b3936.pdfIn PDF document text
    • http://gufutaca6.xyz/84187951314skddf.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://vedixemalirugi.atwebpages.com/aeration_wastewater_treatment.pdfIn PDF document text
    • http://dojorunubi.myartsonline.com/fun_math_worksheets_4th_grade.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e275.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE275 5280 bytes
SHA-256: 7d875eaff501259eba63b687e54486f8856ab615a8c48ca77b049de2fcbfb535
font_01_sfnt_off0000f435.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF435 11540 bytes
SHA-256: b178f8ff4fd566a9ece16239af51f98417c75736c51fa58a941fd54843da0c6d
font_02_sfnt_off00011b86.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11B86 16204 bytes
SHA-256: c988415812f594187b0a0ed75dc52802e798e1695b49bd300f8412a65040a449