Malicious PDF — malware analysis report

Static analysis result for SHA-256 52aaa084376c4946…

MALICIOUS

PDF

76.5 KB Created: 2021-04-04 21:04:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-05
MD5: eaf5f23c99b29180431ae8e45981e787 SHA-1: f0b0ce2752dddd713f2c82d21a815b541db0e17f SHA-256: 52aaa084376c49463b40032b26f84bf725a9d139fb4aed758dcbc5b27af86333
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains a large number of external links, many pointing to disposable hosting services, indicating a link farm or SEO manipulation attempt. ClamAV and ML classifiers flagged this as malicious, specifically a phishing or trojan. The embedded URLs and the heuristic firings suggest the primary goal is to redirect users to potentially malicious content or phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://fusajowaxoxa.weebly.com/uploads/1/3/5/3/135344195/wuvab.pdf In PDF document text
    • https://static.s123-cdn-static.com/uploads/4483104/normal_5fcd27881aac3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4485702/normal_6021d5e653ab5.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4457586/normal_5ffe97bbc57cb.pdfIn PDF document text
    • https://lexeponin.weebly.com/uploads/1/3/1/8/131856664/rulafa.pdfIn PDF document text
    • https://pepedojimu.weebly.com/uploads/1/3/1/0/131069997/xexuvadosojetofif.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4386594/normal_60551ada92204.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365563/normal_6024f950193a8.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4463830/normal_602be26b3459c.pdfIn PDF document text
    • https://jufopikigon.weebly.com/uploads/1/3/4/3/134309667/tugiveja_vereliguruda_puralidebeve_lorosixuxefiwu.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://feedproxy.google.com/~r/wb/ENAH/~3/n4t4wXRn-MA/wb?keyword=wfrp%204e%20monstersPDF link annotation
    • https://52ed6390-a5c1-4502-9f93-599cf6d98ad1.filesusr.com/ugd/f7fbc8_1d4a91c8bda2485ca24c3c14f7035203.pdf?index=trueIn PDF document text
    • https://9169454a-6e45-4b39-89c4-5cd9bf0a6084.filesusr.com/ugd/32fbc8_6b889807ee254f82a6ddcc832d8a4318.pdf?index=trueIn PDF document text
    • https://4121a797-204a-431c-92a8-8e24072fb342.filesusr.com/ugd/b972d5_5f3bfd3478594636b3501cf9b383cbc1.pdf?index=trueIn PDF document text
    • https://1c437d0a-cccb-4a8a-93f1-39e0b5126915.filesusr.com/ugd/b91566_98d467b8fd9849699895bb1ba483cd43.pdf?index=trueIn PDF document text
    • http://romofimor.onlinewebshop.net/what_is_the_story_lather_and_nothing_else_about.pdfIn PDF document text
    • https://aa3bb5c3-2bd4-4791-9e2a-6e31d5009b04.filesusr.com/ugd/60e703_b1dd23512be246cdbaf3b72697ab782c.pdf?index=trueIn PDF document text
    • https://667abc8f-92ca-45d9-bc9d-789c80a68858.filesusr.com/ugd/dcd78f_a45a007693864a9a9c50127bc022f210.pdf?index=trueIn PDF document text
    • https://8d6920c1-aef5-45ed-b1a0-e693d63948fb.filesusr.com/ugd/0a593f_77a684cbb8e94051b3bae3405e0cb90d.pdf?index=trueIn PDF document text
    • https://2ed821ec-8078-4e74-b11b-c5cec6a88262.filesusr.com/ugd/65e777_bfb386d31a4646e9a1b11b994607b3c2.pdf?index=trueIn PDF document text
    • https://0ca3454e-05ac-49fc-8d00-644b1af7be3c.filesusr.com/ugd/8bf3fc_c68ce3ebd5f64a2a8069b78e1a697ec6.pdf?index=trueIn PDF document text
    • http://gakajitaju.atwebpages.com/lsu_gameday_parking_pass.pdfIn PDF document text
    • https://c6b89c2f-dc7d-490d-a648-077c51828da9.filesusr.com/ugd/29ab01_f5879e4618d14610943c3e8ef49aca8a.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ee73.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEE73 4908 bytes
SHA-256: 33df3d5b2bec562230baa1f55d5bdd24fb7e29778917aa9d376a38518def8f42
font_01_sfnt_off0000ff27.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFF27 11124 bytes
SHA-256: 423b30bb5c5bb536513c793bb6158727ea47904397349ebd65f227d8ff907e99