Malicious PDF — malware analysis report

Static analysis result for SHA-256 98f96085dbf5fc1a…

MALICIOUS

PDF

37.8 KB Created: 2020-10-09 22:44:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-07-08
MD5: dfb5b65ab9dca5fe49114ceaa52a2d54 SHA-1: f96ed3adb4ef52bb752495f7262cc1b8b1fffdf8 SHA-256: 98f96085dbf5fc1abf4d9273461eec3e75af7e89099d1cca94a2edd871859600
234 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 6

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Travel-support phone-number stuffing scam high SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?keyword=brainpop+roman+republic+worksheet+answers In PDF document text
    • http://dalix.janetahrens.org/uploads/1/3/1/3/131378960/vomenonanusirob.pdfIn PDF document text
    • http://boluro.platnymscloset.com/uploads/1/3/1/4/131406515/5568462.pdfIn PDF document text
    • http://xetudadem.burleybridge.com/uploads/1/3/1/0/131070469/5374869.pdfIn PDF document text
    • http://www.ascendercorp.com/In extracted file (font_00_sfnt_off00005372.bin)
    • http://www.ascendercorp.com/typedesigners.htmlIn extracted file (font_00_sfnt_off00005372.bin)
    • https://uploads.strikinglycdn.com/files/26a14dee-025e-4a0d-9f38-ed265a1267db/gefawunuridunarito.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c4e6c208-ae46-4032-9d34-e5d4388e2531/sajokomaveveram.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/beedbe65-e8be-4a69-9085-af5f1305513a/wunevoverejuroj.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a3bf1ab3-56af-44e7-9d98-29ff9165fcfd/31166939053.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/189c3e41-5cbc-41aa-b75b-1529f4544d83/giletokuvomuribodo.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0431/5014/7745/files/sijanizedojodulizosu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/be6787b7-0c66-4735-a9cb-5927485be5ec/zagegokulojagamugiz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/542444dd-757e-4352-99c9-0ad4eea0ff10/nogug.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/387f73c7-278a-4650-87ba-b33bcbdb9561/kafejotolo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2847577b-3e85-40ee-959b-6c4535dd41b8/zuxatarufoso.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn extracted file (font_00_sfnt_off00005372.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005372.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5372 5516 bytes
SHA-256: f874dd1687efe5f5c74c9ae060fa4e3b16da79d0a3174e8f90f1ef9f406fe5e7
font_01_sfnt_off00006613.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6613 10764 bytes
SHA-256: a9d34ae92d4c3a0bd1c0670329d3e3fd3dfcdf9eb5d5d12e683f05e5b83b04a0