Malicious PDF — malware analysis report

Static analysis result for SHA-256 72bf25894123db95…

MALICIOUS

PDF

201.8 KB Created: 2018-04-28 13:19:06 +03:00 Authoring application: wkhtmltopdf 0.12.4 (via Qt 4.8.7) First seen: 2026-06-28
MD5: 1a21a5cf801d3e5074e3848ea4a70f30 SHA-1: 8c64b3da2bf1cea2e3b13b69d3e99cfee05bb7dc SHA-256: 72bf25894123db953b4de1d1e5a4b7b55986dbc6731a579faa683ce84bb7f199
74 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.7668

Heuristics 3

  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tds.advtraff2014.ru/wp1?keyword=%D0%B3%D0%B4%D0%B7+%D1%80%D1%83%D1%81%D1%81%D0%BA%D0%B8%D0%B9+6+%D0%BA%D0%BB%D0%B0%D1%81%D1%81+%D0%BB%D0%B0%D0%B4%D1%8B%D0%B6%D0%B5%D0%BD%D1%81%D0%BA%D0%B0%D1%8F+%D0%B1%D0%B0%D1%80%D0%B0%D0%BD%D0%BE%D0%B2+%D1%82%D1%80%D0%BE%D1%81%D1%82%D0%B5%D0%BD%D1%86%D0%BE%D0%B2%D0%B0 PDF link annotation
    • http://tds.advtraff2014.ru/wp1?keyword=%D0%B3%D0%B4%D0%B7+%D1%80%D1%83%D1%81%D1%81%D0%BA%D0%B8%D0%B9+6+%D0%BA%D0%BB%D0%B0%D1%81%D1%81+%D0%BB%D0%B0%D0%B4%D1%8B%D0%B6%D0%B5%D0%BD%D1%81%D0%BA%D0%B0%D1%8F+%D0%B1%D0%B0%D1%80%D0%B0%D0%BD%D0%BE%D0%B2+%D1%82%D1%80%D0%BE%D1%81%D1%82%D0%B5%D0%BD%D1%86%D0%BE%DPDF link annotation
    • https://tibuxumaceseriri.files.wordpress.com/2018/04/gulinesudonulab-gdz-biologiia-9-klass-rabochaia-tetrad-ragasodexif.pdfIn PDF document text
    • https://img0.liveinternet.ru/images/attach/d/0//5918/5918121_wuzuxonadobereader2009downloadforwindows7free64bitsetupnet.pdfIn PDF document text
    • https://momuvagecisij.files.wordpress.com/2018/04/sesotin-algoritm-napisaniia-sochineniia-v-11-klasse-na-ege-bodudoxu.pdfIn PDF document text
    • https://jokomexuvicocari.files.wordpress.com/2018/04/kobotutiwapife-gdz-po-fizike-9-klass-peryshkin-2008-uchebnik-sejasusawekena.pdfIn PDF document text
    • https://cebokufe.files.wordpress.com/2018/04/romodub-sbornik-zadach-po-teorii-veroiatnostei-mukhin-smorkalova-reshebnik-taretotusuwide.pdfIn PDF document text
    • https://xafuqaniqehigib.files.wordpress.com/2018/04/lifegakem-gdz-po-russkomu-iazyku-8-klass-fgos-lvov-lvova-mobujege.pdfIn PDF document text
    • https://jokomexuvicocari.files.wordpress.com/2018/04/juvuverawaj-frants-8-klass-gdz-gumiku.pdfIn PDF document text
    • https://rimokuqubusatohop.files.wordpress.com/2018/04/movotunuvaxene-tsybulko-russkii-iazyk-2016-ege-onlain-chitat-besplatno-zebuva.pdfIn PDF document text
    • https://tibuxumaceseriri.files.wordpress.com/2018/04/guxafomuwode-gdz-po-matematike-6-klass-vilenkin-1577-weroleligirujeb.pdfIn PDF document text
    • https://cebokufe.files.wordpress.com/2018/04/vubab-6-kl-matematika-vilenkin-gdz-674-forovila.pdfIn PDF document text
    • https://img0.liveinternet.ru/images/attach/d/0//5906/5906208_kokoxegeporusskomuchtovkhoditwotud.pdfIn PDF document text
    • https://kugadicusevasejujek.files.wordpress.com/2018/04/tedarabole-zadachnik-po-algebre-8-klass-zvavich-reshebnik-rowutozulidix.pdfIn PDF document text
    • https://img0.liveinternet.ru/images/attach/d/0//5914/5914987_xamexgdzpoangliiskomu9klassnewopportunitieslanguagepowerbookfos.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off0000a4ab.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xA4AB 1485561 bytes
SHA-256: 1718db8b7c6a44712dc1b3acee434281abf7527ebf6ea299260c2277eb5af585
font_00_sfnt_off0002c192.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2C192 29376 bytes
SHA-256: 064fe8334851d506a2307f4fd55050218748e91ab340323c6231ca70dbe4fffc
font_01_sfnt_off000304c2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x304C2 16092 bytes
SHA-256: 6a67702ca4b16ef7f531432cf3a6c5949790ae720254057f8546be72dfcb7c1a