Malicious PDF — malware analysis report

Static analysis result for SHA-256 3cdf1d80ca6482af…

MALICIOUS

PDF

32.6 KB Created: 2020-11-09 16:33:13 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-04
MD5: 55ff7c889c6e128a9db95e37f7639ae2 SHA-1: c777415c61c938c3e29a2ede818d0da305615885 SHA-256: 3cdf1d80ca6482af13f6b1fb88d0cfa4af9a54786551ea45276a96e5c92604ae
74 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains heuristics indicating it is malicious and uses an SEO redirector for a 'free-download phishing' lure. The document body, though heavily obfuscated, contains a URL that is also flagged as a high-priority IOC. The ML classifier strongly indicates maliciousness, suggesting the PDF is designed to lead the user to a harmful site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 3

  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/aws?keyword=porunga+dragon+balls+dokkan+battle PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4415304/normal_5f946e2dcb8b2.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4443344/normal_5f9c7deb53e5f.pdfIn PDF document text
    • https://s3.amazonaws.com/samopakamefap/20004905359.pdfIn PDF document text
    • https://s3.amazonaws.com/xalasawu/57113853157.pdfIn PDF document text
    • https://s3.amazonaws.com/juduk/bulking_workout.pdfIn PDF document text
    • https://s3.amazonaws.com/kavitokolezub/anemia_hemolitica_en_el_embarazo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/89744426-2699-4bfd-a8b8-198b5d9176e6/thinking_fast_and_slow_book_summary.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4b7ae04c-8796-4537-acf2-48c4c3fab78f/como_hacer_una_presentacion_en_power_point_formal.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/db16d26f-7d80-4307-8724-7c0db0e29a66/95936800698.pdfIn PDF document text
    • https://s3.amazonaws.com/bodepova/98691768004.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f0187857-6dc0-4f5d-b2de-a8777988acac/kebolopedebipodakoju.pdfIn PDF document text
    • https://s3.amazonaws.com/vavapekadoliti/10082532298.pdfIn PDF document text