Malicious PDF — malware analysis report

Static analysis result for SHA-256 943ec5fe9659ff4f…

MALICIOUS

PDF

76.7 KB Created: 2021-03-18 08:21:58 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-04
MD5: 9260fe68b4e1cd2f11e98c4f7b4c396d SHA-1: dcdcdeeb32bcff8d5718007bba504beacd699ad6 SHA-256: 943ec5fe9659ff4f6b5960d22a4061899594590c5660d7d3962d06812101d390
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier, indicating a phishing attempt. It contains numerous external URIs, including one pointing to 'vilenefex.ru', suggesting a lure to a malicious site. The document body, though heavily obfuscated, appears to contain search-related keywords, reinforcing the phishing pretext.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/strik?utm_term=how+hard+is+ib+math+aa+hl PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4467576/normal_5fdee62f3db85.pdfIn PDF document text
    • http://kazexajisodibu.medianewsonline.com/55664017546.pdfIn PDF document text
    • http://nituzovido.getenjoyment.net/calories_in_fresco_style_taco_bell.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4419204/normal_5fff95dc357e7.pdfIn PDF document text
    • https://s3.amazonaws.com/tuxenipup/midabuwiwezibixefaxale.pdfIn PDF document text
    • https://s3.amazonaws.com/lofese/share_chat_ringtones_telugu_2019_love.pdfIn PDF document text
    • https://s3.amazonaws.com/dotivaf/14199425295.pdfIn PDF document text
    • http://digovin.getenjoyment.net/the_real_guitar_book_volume_1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4388158/normal_6016387fa548b.pdfIn PDF document text
    • https://s3.amazonaws.com/bifadiwuwileji/84392772414.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://e905e09d-7ddd-4aab-833c-73500e817873.filesusr.com/ugd/f4c08b_e98ad3e30ece40758c1c62c8e6c61f29.pdf?index=trueIn PDF document text
    • https://1e8c0764-4a0f-46ab-84a2-5f63a8a44928.filesusr.com/ugd/6a0acf_0f80ff7c20474688adbacfa66c3f7f15.pdf?index=trueIn PDF document text
    • https://51da6a7d-ee05-4a49-87ee-1b74af3aeb07.filesusr.com/ugd/b80405_5c0ab03c7e1243eda11ab481338e5a02.pdf?index=trueIn PDF document text
    • http://zenakezogutomu.onlinewebshop.net/18066474709.pdfIn PDF document text
    • https://8c285b57-3156-47ce-881b-df665acc117b.filesusr.com/ugd/8d46c2_5b7758188f63465b862b9a23a8adab21.pdf?index=trueIn PDF document text
    • https://72dfff08-f6cb-4f5d-aaac-ebe71175d6a6.filesusr.com/ugd/c268f7_1107cf8d23db4847aa3bc973b3f98795.pdf?index=trueIn PDF document text
    • http://futikuzita.onlinewebshop.net/doxor.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000edea.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEDEA 5256 bytes
SHA-256: 0a142ca037048cbb767cb142743878f75b7e9d6022caa9cc923d05639425510f
font_01_sfnt_off0000ffa7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFFA7 10736 bytes
SHA-256: 807a563c0eed787b0dfdd67c6298a30a3e136b47bb9856da1c77ddef9508a006