Malicious PDF — malware analysis report

Static analysis result for SHA-256 954f7ea06f8c54c0…

MALICIOUS

PDF

44.9 KB Created: 2021-03-18 09:26:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-04
MD5: 5043766e5e4640dac44b379d3d684a4a SHA-1: be4e061215e002dcf78da5c2d54498a8c1e6cd39 SHA-256: 954f7ea06f8c54c0f1037759f0a814a6e6d4daceb2ef081623652cbf301f560a
182 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded URLs, many of which point to suspicious or unknown domains, indicating a link farm designed to redirect users to malicious content. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' specifically flags a URL leading to known malicious infrastructure. The ML classifier and ClamAV detection further support the malicious nature of this PDF, likely used as a phishing or malware distribution vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7595

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/award?keyword=mla+referencing+style+pdf In PDF document text
    • https://static.s123-cdn-static.com/uploads/4372735/normal_5fc60c9735d89.pdfIn PDF document text
    • http://reassurez-moi-fr.info/electrical_calculations_cheat_sheetrasu0.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4380213/normal_60031d5da800d.pdfIn PDF document text
    • http://videohost.space/tumudujuxuxxtu8v.pdfIn PDF document text
    • https://cdn.sqhk.co/wagomito/atchg9t/16351793237.pdfIn PDF document text
    • http://center-about.com/teachers_first_credit_union_mortgage_ratesoj7x6.pdfIn PDF document text
    • http://onsideball.info/723945737693l8ec.pdfIn PDF document text
    • http://vizit.store/how_to_remove_jvc_kw-r910btlp62x.pdfIn PDF document text
    • http://ig-copyrightnotice.com/ejercicios_de_porcentajes_para_secundariagfu24.pdfIn PDF document text
    • https://cdn.sqhk.co/davusegeb/Xhb0Iif/32019172630.pdfIn PDF document text
    • http://opit.space/stc-1000_manual_espaolwg9vb.pdfIn PDF document text
    • https://cdn.sqhk.co/dezorevukor/t5QLWib/musulowevomes.pdfIn PDF document text
    • http://haustova.com/gba_emulator_pro_apkrirq8.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4392215/normal_602534a69ca72.pdfIn PDF document text
    • http://goldalbum.ru/44714926711p1fqv.pdfIn PDF document text
    • http://petrol-v-pol-price.site/babetowaperofe004hf.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4492901/normal_602f606a8955c.pdfIn PDF document text
    • https://cdn.sqhk.co/lulaxujik/AngdjeO/fedoxa.pdfIn PDF document text
    • https://da5bec28-7969-4117-8ffb-5069fce5e80c.filesusr.com/ugd/31593d_c7f427b5da604b738801d344a41661a1.pdf?index=trueIn PDF document text
    • https://729282ec-1290-4cbc-9302-cf8a24acd4c7.filesusr.com/ugd/42c189_666ae275812548d4b8aebcb8938bdc8f.pdf?index=trueIn PDF document text
    • https://f6e2a16f-d004-42cd-8f17-0463e090774c.filesusr.com/ugd/c70c35_94ee3712ff434dff8925e55ce8b9f0df.pdf?index=trueIn PDF document text
    • https://807eaacf-9fb6-4e16-bcb8-061395d1d132.filesusr.com/ugd/a3ef2e_de5b0b2bb84345109996e81737ad49b8.pdf?index=trueIn PDF document text
    • https://1794ee33-230d-455b-98b1-84d48067edce.filesusr.com/ugd/551769_2e26abd1f6024aa5a12c543217d8d42d.pdf?index=trueIn PDF document text