Malicious PDF — malware analysis report

Static analysis result for SHA-256 8f698dcc1c5920d6…

MALICIOUS

PDF

46.2 KB Created: 2020-09-30 15:46:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-04-30
MD5: a92130997bb5e1f2387e881eb643ef01 SHA-1: 878b5ea9e5f9e420895a9eda314a39cfddfa39e8 SHA-256: 8f698dcc1c5920d64499d2c5e0e6066c7e2fde23ab8915455a14b0a7f674b9a7
194 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/strik?keyword=everything+i+never+told+you+book+pdf+download+free In PDF document text
    • http://xuralo.38plus2productions.com/uploads/1/3/1/3/131398177/nejuwisugobad.pdfIn PDF document text
    • https://site-1036941.mozfiles.com/files/1036941/83187611920.pdfIn PDF document text
    • https://site-1036730.mozfiles.com/files/1036730/28386057282.pdfIn PDF document text
    • https://site-1037273.mozfiles.com/files/1037273/kizafogebitomejaruxafetul.pdfIn PDF document text
    • http://www.ascendercorp.com/In extracted file (font_00_sfnt_off00007654.bin)
    • http://www.ascendercorp.com/typedesigners.htmlIn extracted file (font_00_sfnt_off00007654.bin)
    • https://uploads.strikinglycdn.com/files/daad4454-f5da-47a0-82e5-a0ade7b1dced/feberas.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a85165d7-32e0-4d2b-a839-33307023a773/57750389454.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/37c666f4-6e7b-4a15-8e57-2dda9a261e24/46882069090.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/98c235a3-5100-4152-957c-a3df6ca0f102/timerodagujeze.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ccbe1657-7b23-4c32-b74b-049599786041/71828916523.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/de7dbf85-b319-45b0-a2d9-1592c7c25845/65053036028.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3ff6ab89-0c3f-4af1-b64a-0c139d4b0b48/fobusefanofozave.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bfecf90f-ec59-40f1-bb9b-809b0fdcbfbf/13463992828.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7493cb85-f42d-4502-83b6-ba47e515abc9/60733792603.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7cd0d7fb-f72c-4b2f-bb6b-f94ca4e54062/18846040036.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn extracted file (font_00_sfnt_off00007654.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007654.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7654 5540 bytes
SHA-256: abba28e681c55b03939bb0f4871ce53b3f14a51040c3fc9b8e6954fb212b570b
font_01_sfnt_off00008944.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8944 10092 bytes
SHA-256: 770698df0aee23bcaa0bccf8ca54976d4a20d20590505befd59767bec2ee2e5e