Malicious PDF — malware analysis report

Static analysis result for SHA-256 906fa03519a7d85b…

MALICIOUS

PDF

76.3 KB Created: 2021-03-27 10:46:50 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-04
MD5: 04ca5c6084187c8979e01b8e6a6b94a2 SHA-1: 3ada2981c9695bd0c95e821ea5fc2ee35785db54 SHA-256: 906fa03519a7d85b127e9a552d54f7a7e52e59c0b1b30d6c2bf373415c15beff
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous embedded links, with one notable URL pointing to 'jottigo.ru'. The 'PDF_SEO_DISPOSABLE_LINK_FARM' heuristic indicates a large number of links on disposable hosting, suggesting a phishing or spam campaign. The ML classifier and ClamAV detection further support the malicious nature of this PDF, likely used as a lure to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8488

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PDFSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/award?keyword=angelus+silesius+libros+pdf PDF link annotation
    • http://setofexperience.site/samsung_nu7100_43_inch_price_in_pakistan5odzk.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374207/normal_6055be4d62c4c.pdfIn PDF document text
    • http://reduslimitalia-oficial.site/ciudad_fantasma_bernardo_esquincas0aer.pdfIn PDF document text
    • https://cdn.sqhk.co/zikonidenijo/bibW83V/11762415641.pdfIn PDF document text
    • http://piredvizhnik.com/game_commando_survival_battleground_mod_apks9z0k.pdfIn PDF document text
    • https://cdn.sqhk.co/fiduzosi/chikheF/66636586068.pdfIn PDF document text
    • http://betizekaxu.getenjoyment.net/how_to_make_cool_science_projects.pdfIn PDF document text
    • http://zekaxezixil.medianewsonline.com/momo_traders_amazon.pdfIn PDF document text
    • http://luminar2-download.xyz/text_to_voice_changer_software_free5gkd6.pdfIn PDF document text
    • https://cdn.sqhk.co/xipepovivik/dgjgfhg/10137249261.pdfIn PDF document text
    • http://botanilix.mygamesonline.org/ias_zoology_syllabus.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4381098/normal_603159714339f.pdfIn PDF document text
    • https://cdn.sqhk.co/rubutemoxe/jgheia5/idle_forge_craft.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4372673/normal_5fd3c2d4b2bae.pdfIn PDF document text
    • http://sovuradema.medianewsonline.com/how_long_do_snow_blowers_last.pdfIn PDF document text
    • https://cdn.sqhk.co/bivuwusim/hkB2GDC/free_streaming_apps_for_xbox_one.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4418963/normal_605d82494a66d.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://9049409e-dcbb-43fe-b7cb-0f7a5d042cf1.filesusr.com/ugd/e59eee_b744d60accbe4e0eab474146427ec47b.pdf?index=trueIn PDF document text
    • http://gogujigasad.onlinewebshop.net/najudiw.pdfIn PDF document text
    • https://dc273c12-e125-4738-b2e6-b96bc4bd5eb7.filesusr.com/ugd/c8df25_37dd890313744bdc8ac1ad19f4e4d4d1.pdf?index=trueIn PDF document text
    • https://72a23b54-95c1-47c0-80d6-f7b1310faeb8.filesusr.com/ugd/65b209_26de11017fc4434cb2b6ba22553e6fd4.pdf?index=trueIn PDF document text
    • http://kozogasivufi.myartsonline.com/bogunanu.pdfIn PDF document text
    • http://gezixus.myartsonline.com/wotis.pdfIn PDF document text
    • https://f8b57e9d-e272-4783-b6f5-6420e6b93425.filesusr.com/ugd/886b73_207e2f7ff9594d1ab6a25012ad9cc43c.pdf?index=trueIn PDF document text
    • http://duxegejuw.atwebpages.com/5039731686.pdfIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f7cf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF7CF 5128 bytes
SHA-256: b6e022022eedaf1c540686d9cbd505f25e3bda70c0f4273ca3aa8c36abc69978
font_01_sfnt_off00010950.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10950 12572 bytes
SHA-256: 1041dbadf75dcbc257f270b86f917a7732c539a5331149109d5eeeacbdf6cf28