Malicious PDF — malware analysis report

Static analysis result for SHA-256 6621d5bf4288f785…

MALICIOUS

PDF

39.2 KB Created: 2020-10-31 04:33:10 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-05
MD5: c7136af103d296b320d7c354ba4ea8ab SHA-1: b9ea470dea61e12ac919eb40b2802774b28e988b SHA-256: 6621d5bf4288f785baa0b58ec3b2e43a1c984fd43858d2cd168986f90cb727a4
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, many of which point to redirector infrastructure and link farms, indicating a malicious intent to direct users to potentially harmful websites. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9952

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/wb?keyword=probability%20questions%20grade%207%20pdf In PDF document text
    • https://gemiwanot.weebly.com/uploads/1/3/4/4/134495393/8818254.pdfIn PDF document text
    • https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/4106527.pdfIn PDF document text
    • https://folanejo.weebly.com/uploads/1/3/0/7/130776558/gumipogulokam.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4388827/normal_5f90af3c53258.pdfIn PDF document text
    • https://guburumo.weebly.com/uploads/1/3/4/3/134322172/0c4ebb.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4383912/normal_5f97cd37a5d7a.pdfIn PDF document text
    • https://nulumekut.weebly.com/uploads/1/3/4/3/134373747/xotizowu-suvem-fuxazukawituv.pdfIn PDF document text
    • https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/7934e45822a5c.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c540f3bd-6bf7-4608-8241-426e124b7568/xefaxamo.pdfIn PDF document text
    • https://s3.amazonaws.com/podawakumepewez/easy_ukulele_tabs.pdfIn PDF document text
    • https://s3.amazonaws.com/subud/91159771546.pdfIn PDF document text
    • https://s3.amazonaws.com/xanebavifamopez/92468426639.pdfIn PDF document text
    • https://s3.amazonaws.com/saziwijaxodav/barrow_county_jail_address.pdfIn PDF document text
    • https://s3.amazonaws.com/pujinit/2018_calendar_with_indian_holidays_download.pdfIn PDF document text