Malicious PDF — malware analysis report

Static analysis result for SHA-256 b6e381b74acd33ee…

MALICIOUS

PDF

45.9 KB Created: 2020-09-30 20:18:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-05-17
MD5: 6774d603d78c09529a353a5966e2b8fb SHA-1: 3c8e573fb8617b59c4830d90fcb1884dbd9d77e8 SHA-256: b6e381b74acd33ee5e3ea558f84036a36d79f84776620c51d5e574c9d160897e
194 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/strik?keyword=russian+beginner+vocabulary+pdf In PDF document text
    • http://duxupa.howardinteriordesign.com/uploads/1/3/0/7/130739347/5f904.pdfIn PDF document text
    • http://files.seantheprankster.com/uploads/1/3/0/7/130776828/4147275.pdfIn PDF document text
    • http://www.ascendercorp.com/In extracted file (font_00_sfnt_off000073bf.bin)
    • http://www.ascendercorp.com/typedesigners.htmlIn extracted file (font_00_sfnt_off000073bf.bin)
    • https://uploads.strikinglycdn.com/files/7b683eb0-a78d-494b-84f3-d38d6edf7f69/1981386713.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/06502603-99ac-4708-8c74-53e90dd51c4b/19514909354.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2aa2d3a0-b628-4248-9d39-ad3c9325858f/79211443556.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b4be7b17-6a7b-40d2-8087-16e1e5712559/vizimijinaxadakan.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0470ecba-b886-45d8-b6b5-35cc0a9aa5af/riwekutawijol.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/8542/1978/files/iit_foundation_maths_books_for_class_8_free_download.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/4317/6091/files/abraham_twerski_kitaplar.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/faff606c-aeff-4ffe-b8b5-772b10a4e8d9/tuvatitotidix.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e1d61de1-7a64-419b-9e15-32a5dcfe169d/86064370548.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bf162227-32c3-4999-93a6-320cc01c93e4/99532623744.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1c28b3d0-ae15-44ea-b171-89e2c5006ddc/pekumulukisezonovaretej.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/44a2780d-e2b5-4815-a021-f1656c6ab272/jowuribite.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn extracted file (font_00_sfnt_off000073bf.bin)
🗂 Part of campaign: martismixedmedia.com 3 samples

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000073bf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x73BF 5632 bytes
SHA-256: dedfc8ba943c5edeaecd1adacd57a45811112780df77ec953426ff2f66ad2062
font_01_sfnt_off00008708.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8708 10496 bytes
SHA-256: 740e7bb4982706f5d50bb3c66d31b55ec0f88659cc72c7ada06b05418811b1fb