Malicious PDF — malware analysis report

Static analysis result for SHA-256 7e0bd93cbc528249…

MALICIOUS

PDF

42.7 KB Created: 2020-10-09 18:08:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-05-11
MD5: 579dd6c2be0a1358404adcb4cfc7c0be SHA-1: 45028b6c7a2733f246191adc864f1d715e819427 SHA-256: 7e0bd93cbc5282496b771d7683a9e116a49c577722b64c2b73e86afa1be11b57
194 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?keyword=the+other+wes+moore+important+quotes In PDF document text
    • http://files.shamanjessica.com/uploads/1/3/2/7/132741029/c949044ac8ed.pdfIn PDF document text
    • http://files.becomingafamilydoc.ca/uploads/1/3/1/4/131454373/nijoxum_vejobejulagu_vogonajifupi_duwedikaz.pdfIn PDF document text
    • http://files.topshotacademy.us/uploads/1/3/1/1/131164159/tusatesozuxiri_wabozufu_diwikawadalubo_rajozosesiga.pdfIn PDF document text
    • http://www.ascendercorp.com/In extracted file (font_00_sfnt_off00006a82.bin)
    • http://www.ascendercorp.com/typedesigners.htmlIn extracted file (font_00_sfnt_off00006a82.bin)
    • https://uploads.strikinglycdn.com/files/3ce7a710-692d-45a7-b803-939f2bfb108f/sodixofigotejeteb.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1c4b0802-de10-41b2-ba48-222de5b71878/zaretewenoton.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8a9cd3d5-7e25-4ad8-8a1b-5dbd7c93a709/fugur.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4cb26471-b78b-4558-9e3c-7290077ba3ff/46648488710.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f42bfaa0-e612-4665-a86f-318e8de8fcda/43068191181.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dd7a24af-ec87-4dd1-9f11-9bb687530b44/kafakifujexij.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/53ffad0d-ab0a-488b-97f9-ec26549efb90/23354275161.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b06a02f0-3627-4cba-8e23-8dc63bc8701e/datoboropebogol.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0cfa76f4-cfcf-4503-aabc-70f35f7a27cf/43455965669.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bc822802-733d-4e83-93e2-5ed653bf1476/nifolalawo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8ce7a759-001b-48e2-80c7-1e774debe31c/30917847560.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn extracted file (font_00_sfnt_off00006a82.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006a82.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6A82 5196 bytes
SHA-256: 54522a2d2ab3c8d05d94fbdd953dc2f59d315de93a5dc0b3d809179d2ccb8c04
font_01_sfnt_off00007c10.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7C10 9992 bytes
SHA-256: f193a65cbb43381f3ce226527816c7a5d2a1622c69abf43e9b1eb5e026a62d5e