Malicious PDF — malware analysis report

Static analysis result for SHA-256 25c4f07c26e745a0…

MALICIOUS

PDF

88.3 KB Created: 2021-12-07 23:23:48 +03:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2026-04-01
MD5: 0c2739f8282808dde1e4cd714a5d9515 SHA-1: 3f05219325f3216eaa0c6609c2540771ea27a09f SHA-256: 25c4f07c26e745a0c5fad7de774bc4f1837aef28bd92d0871fcb0aeba1268b48
99 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0384

Heuristics 5

  • Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LURE
    Document describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
  • PDF carries website-builder CDN document link farm medium PDF_CDN_PDF_LINK_FARM
    PDF contains many clickable PDF links parked on website-builder CDNs or simple download gateways together with visible ebook, manual, or download lure text. This matches generated SEO document carriers used to route users through untrusted link/download chains; the PDF itself is an inert link carrier.
  • PDF links to disposable redirector campaign host medium PDF_DISPOSABLE_REDIRECTOR_CAMPAIGN
    PDF's outbound link points to a throwaway redirector domain that recurs as the sole redirect across a large family of otherwise unrelated spam PDFs (movie-piracy, affiliate, and viral-link lures). These domains appear on no reputable list and exist only to funnel openers into malvertising / scam / download chains.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://getpdf.pw/book?res=strik&isbn=9781616895853&kwd=Color%20Theory%20Notecards PDF link annotation
    • https://files8.webydo.com/9588972/UploadedFiles/BAEA85EB-5DB7-12C2-8C33-27935F5A9A55.pdfIn PDF document text
    • https://static.s123-cdn-static-a.com/uploads/4659632/normal_61ad5f624da1b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4659407/normal_61add78c936dc.pdfIn PDF document text
    • https://static.s123-cdn-static-c.com/uploads/4659620/normal_61adfe881e5be.pdfIn PDF document text
    • https://static.s123-cdn-static-a.com/uploads/4659603/normal_61ade565af849.pdfIn PDF document text
    • https://files8.webydo.com/9588904/UploadedFiles/048281B1-35D0-E545-7597-DD27E1A97311.pdfIn PDF document text
    • https://img1.wsimg.com/blobby/go/0b5c5f4b-a500-431f-b781-1dcbfcc94a10/second-chance-pass-478.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn extracted file (stream_006_off0001035e.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off0001035e.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1035E 22156 bytes
SHA-256: e99743789bd533539effb4795b3f3cc16668ed9d5290a10961068e62e2b9066f
font_01_sfnt_off00013702.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13702 18616 bytes
SHA-256: 6aae62537ea822b8185cd89762c4ba192ee9ea1f153521d05f4b2bb0bd970405