Malicious PDF — malware analysis report

Static analysis result for SHA-256 3a4df639acc3b34c…

MALICIOUS

PDF

122.8 KB Created: 2021-03-23 15:09:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-04
MD5: c32b1580f65ebddb92ea10c5364d2f18 SHA-1: 29e4fa2e041112ed4e3bc22db21920cc518e681a SHA-256: 3a4df639acc3b34cf6910c3e5fe4834c3ce9112c0c4d2341dfac833532120308
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains a link farm with numerous external URLs, including one pointing to 'soxebez.ru', suggesting it's used for phishing or distributing further malware. The document body, though heavily obfuscated, appears to be a lure related to '2019 all movies tamil hd'. No scripts were extracted, but the PDF structure itself is used to host and link to external content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9982

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/123?utm_term=2019+all+movies+tamil+hd PDF link annotation
    • https://cdn.sqhk.co/vowibesep/fKJibcC/cup_stacking_song_pitch_perfect.pdfIn PDF document text
    • http://streamsweets.com/easy_ice_cream_recipe_without_machinellas2.pdfIn PDF document text
    • https://cdn.sqhk.co/kopilixa/gZnhcwK/minecraft_exploration_mods_1._12._2.pdfIn PDF document text
    • http://mon-compte-cmb.best/tft_set_4_warlord_spatulaaiucc.pdfIn PDF document text
    • http://sreda.city/pioneer_avh-200bt_manualhly26.pdfIn PDF document text
    • https://cdn.sqhk.co/jezaziritav/hahcGia/tosok.pdfIn PDF document text
    • http://kmplitka.shop/survivalcraft_2_download_pc9eiux.pdfIn PDF document text
    • http://jobauthor.online/gokoterixivghunj.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • https://920f4c01-5fd6-4c40-8b27-b99972fecb60.filesusr.com/ugd/d63aaf_dc423f1cccc64399afb963a597728ed4.pdf?index=trueIn PDF document text
    • https://d1b33a7b-cde1-45d4-bc15-d4d3b6236ac5.filesusr.com/ugd/1d64af_e6fcc2670069423e9415707f6279f9fc.pdf?index=trueIn PDF document text
    • https://6f672a44-e16c-4921-a0f1-e3781c0647c5.filesusr.com/ugd/bda22a_9cd1183cc4ed42078020b9ca5ca304c2.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/07422f7f-b19e-421c-8c59-e28b06faf95e/juxokejemosesovubiwida.pdfIn PDF document text
    • https://ddf64d59-5240-4154-9987-17dfc28e22c7.filesusr.com/ugd/cec570_3557a3fb5f72469ba0d20b91706e8d61.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/89d5fe11-de76-4cf6-b662-1fd9df9a69a5/who_won_sexiest_man_alive_2015.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5b8f0202-d795-4d07-95ae-951d932ac820/how_to_change_the_battery_in_a_harmony_remote.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b5460601-ab4f-4130-8ffb-5c09ddb903e7/wii_u_console_for_sale_near_me.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4da8029f-bb4a-494d-9852-cc55abfccc61/satomasomazifageguvotep.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/09741b1d-041f-4f6b-af2b-259ba10fa150/wunusoxubira.pdfIn PDF document text
    • https://bb209e34-24c3-4901-88bd-c00af8cda710.filesusr.com/ugd/de6798_e3f88dcc1d174f0ab13ddbea72d36152.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/3fdf2edc-a8cc-4fa2-ae5e-20f2859464de/settlers_of_catan_card_size.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fb760824-3692-4b0b-9f24-78a9f1708836/how_to_study_physiology_in_medical_school_reddit.pdfIn PDF document text
    • https://dcc20dec-0195-4543-b617-cfb82efd15f0.filesusr.com/ugd/30ea26_a717c7d8a25148f1990b3dcc7225724f.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/6b80a875-7ae6-4e33-8fa7-18866d4680ec/gibatuw.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/45273c01-d5bf-4c35-af26-94e89eaddfe2/panasonic_kx-tga939t_belt_clip.pdfIn PDF document text
    • https://7fd92c66-d3af-485c-b7a9-31529ddfb1b5.filesusr.com/ugd/997d0f_ba186c368a2a445ea4c6357e9c990fea.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00017798.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x17798 5416 bytes
SHA-256: 61c34180ec4a10c492ac3cde577902d5a8e9c12e2a77109be907578c6969959d
font_01_sfnt_off000189de.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x189DE 6664 bytes
SHA-256: d1d7f97ecb14f999f857a2b0b08ba4ad45d4691a9c0ced98cf08e982ed6a6966
font_02_sfnt_off00019eef.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x19EEF 11888 bytes
SHA-256: 49c92116c879d2072cba346d624f9bae5eadfc260d9377922b301691f82147ee
font_03_sfnt_off0001c7a5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1C7A5 16164 bytes
SHA-256: 6e3fbd491d8b71441998836ddca0d0c102716a221ea14f8143929167ad9a79b3