Malicious PDF — malware analysis report

Static analysis result for SHA-256 809010f04314430a…

MALICIOUS

PDF

95.6 KB Created: 2021-12-09 21:33:08 +03:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2026-04-01
MD5: 2ae92c9798a3f238911c671005492f43 SHA-1: 77811be223e0d6bc2ffe33c8d956b68bf2d91b41 SHA-256: 809010f04314430a9ce1e30a796e5467e6b57fdce00ea6c58fe72bd753897136
67 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0592

Heuristics 5

  • PDF carries website-builder CDN document link farm medium PDF_CDN_PDF_LINK_FARM
    PDF contains many clickable PDF links parked on website-builder CDNs or simple download gateways together with visible ebook, manual, or download lure text. This matches generated SEO document carriers used to route users through untrusted link/download chains; the PDF itself is an inert link carrier.
  • PDF links to disposable redirector campaign host medium PDF_DISPOSABLE_REDIRECTOR_CAMPAIGN
    PDF's outbound link points to a throwaway redirector domain that recurs as the sole redirect across a large family of otherwise unrelated spam PDFs (movie-piracy, affiliate, and viral-link lures). These domains appear on no reputable list and exist only to funnel openers into malvertising / scam / download chains.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://getpdf.pw/book?res=strik&isbn=9781107601758&kwd=Ethics%20and%20Health%20Care%20:%20An%20Introduction PDF link annotation
    • https://static.s123-cdn-static-d.com/uploads/4661671/normal_61b0a2de5563f.pdfIn PDF document text
    • https://files8.webydo.com/9589139/UploadedFiles/DAD29FF2-0CD8-61BB-FD6A-507A150E2761.pdfIn PDF document text
    • https://static.s123-cdn-static-a.com/uploads/4661453/normal_61b02e55e9f12.pdfIn PDF document text
    • https://files8.webydo.com/9589135/UploadedFiles/1BC80D9B-A579-252C-D3F6-9B0842FD91D2.pdfIn PDF document text
    • https://files8.webydo.com/9589087/UploadedFiles/1F0E4797-09ED-A333-EDAD-A97985F05ED8.pdfIn PDF document text
    • https://files8.webydo.com/9589153/UploadedFiles/EDC4E78A-BAF0-768C-DF3C-211D69CAE208.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4659946/normal_61b07f73ef052.pdfIn PDF document text
    • https://img1.wsimg.com/blobby/go/0896f0a8-b7a9-43de-a17e-a257f6368b00/funny-stories-for-7-year-olds-73.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn extracted file (stream_007_off00011d3b.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_007_off00011d3b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x11D3B 22260 bytes
SHA-256: cd468c6cb95fea7a2db44927e27d182cc68a6098001e887479a180f0caa8a759
font_01_sfnt_off0001514d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1514D 19376 bytes
SHA-256: 90d8065ef11291ee1fc9c9bb9e8f97efd7be4fa2323c183ba801dd80999eb82a