Malicious PDF — malware analysis report

Static analysis result for SHA-256 a9c0d65c008ffd20…

MALICIOUS

PDF

91.9 KB Created: 2021-12-09 00:51:21 +03:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2026-04-27
MD5: e1c89facfbac4595acfbc3cfdff58e81 SHA-1: 58f9d8097b0b4575279dc0a2fdb91596cc27479c SHA-256: a9c0d65c008ffd201e4442951d907556d6ebe25079dc5905706ff98eeb1832fa
99 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0349

Heuristics 5

  • Travel-support phone-number stuffing scam high SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • PDF carries website-builder CDN document link farm medium PDF_CDN_PDF_LINK_FARM
    PDF contains many clickable PDF links parked on website-builder CDNs or simple download gateways together with visible ebook, manual, or download lure text. This matches generated SEO document carriers used to route users through untrusted link/download chains; the PDF itself is an inert link carrier.
  • PDF links to disposable redirector campaign host medium PDF_DISPOSABLE_REDIRECTOR_CAMPAIGN
    PDF's outbound link points to a throwaway redirector domain that recurs as the sole redirect across a large family of otherwise unrelated spam PDFs (movie-piracy, affiliate, and viral-link lures). These domains appear on no reputable list and exist only to funnel openers into malvertising / scam / download chains.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://getpdf.pw/book?res=strik&isbn=9780982365311&kwd=Mike%20Slack%20:%20Pyramids PDF link annotation
    • https://static.s123-cdn-static-a.com/uploads/4661333/normal_61b111216245c.pdfIn PDF document text
    • https://static.s123-cdn-static-d.com/uploads/4660054/normal_61afec5525d0c.pdfIn PDF document text
    • https://static.s123-cdn-static-d.com/uploads/4659931/normal_61b07ecc7e7e5.pdfIn PDF document text
    • https://static.s123-cdn-static-b.com/uploads/4660730/normal_61b02603d41be.pdfIn PDF document text
    • https://static.s123-cdn-static-c.com/uploads/4660484/normal_61b0b604cfab9.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7e73e719-80a7-4f26-9ca8-b669e7db262c/frida-kahlo-the-complete-paintings-580.pdfIn PDF document text
    • https://img1.wsimg.com/blobby/go/c13fdbc5-9ef9-4c77-877c-8b3d21a4dc5a/the-queen-of-wishful-thinking-291.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn extracted file (font_00_sfnt_off00011125.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011125.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11125 22064 bytes
SHA-256: 39457777434f438f6892fc709fefdb222c189331d30c94de40b4766edd250f56
font_01_sfnt_off00014444.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14444 18740 bytes
SHA-256: bcaa4226789ceead2482d22be9a0a09e4953033d64c8c112cae354ca7798949d