Malicious PDF — malware analysis report

Static analysis result for SHA-256 bab6296ef6e05e86…

MALICIOUS

PDF

87.8 KB Created: 2021-07-22 06:59:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-06-04
MD5: b57e71ea3b654ce47135e36a70447ad8 SHA-1: 36f86e00bbf41dfed27948f6bfb28ad3d3e6d004 SHA-256: bab6296ef6e05e865eff7eccecd810085c80a527dbdcea4f5f3f7330e01aafbe
76 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The ML classifier strongly indicated maliciousness in this PDF. The document contains embedded URLs that likely serve as lures to malicious sites, suggesting a phishing or credential harvesting attempt. Although no scripts were explicitly extracted, the presence of embedded URLs and the ML detection point towards a malicious intent, likely related to spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://feedproxy.google.com/~r/sq/ugae/~3/IdU8rIDf9lQ/square?utm_term=anglo+saxon+alfred+the+great PDF link annotation
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e889fe8454a77d57b97358/1625852414455/missing_comma_after_introductory_element.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60edfbf68e89d93564d81daf/1626209271126/12753105090.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f86d2abd6002733acdc919/1626893610378/house_of_night_cast.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f1844f133357608f408c33/1626440783714/surface_area_of_a_hexagonal_prism_calculator.pdfIn PDF document text
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e8d648c4ce500af844de16/1625871944945/cubs_theme_song.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60ec87365978cb5ccaab2929/1626113846439/kokoremo.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e80a4a4d2175279d154d53/1625819722097/fuzetimuj.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f6385a285ce460d19c5adc/1626749018896/rixazikezalabuvej.pdfIn PDF document text
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60f065d0be875f230105f052/1626367441171/a_to_z_telugu_dj_mp3_songs_download.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f32d9c503a2167178fa26d/1626549660725/mulavarexiz.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60ee7d199c71001bedf966cf/1626242329863/to_look_up_in_spanish.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60eddf764c056a31b81b4663/1626201974420/what_do_you_like_to_do_in_your_free_time_answer.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60edd9b74c056a31b81a9bd3/1626200504021/koxivilabijapetuzob.pdfIn PDF document text
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f5a6a99125bc780f5dc762/1626711721599/68481867231.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ec8d69243eac6055cf81c2/1626115433148/18044298111.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f6709f4742d44d70724107/1626763423921/you_are_better.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e8ef6cfc46b1505825e040/1625878380598/on_the_jellicoe_road_download.pdfIn PDF document text
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60eda735c8cbd011b90cc784/1626187573533/tusiz.pdfIn PDF document text
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60f64e1e351e882d9241016c/1626754590428/44790612001.pdfIn PDF document text
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ee45ca7d49fb55d627ef9c/1626228170408/2017_form_4562_instructions.pdfIn PDF document text
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60efdd4b91893d3c03940e44/1626332491377/wimezeratireda.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f42f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF42F 10624 bytes
SHA-256: ae9ff55b9a0fb8dc62b3e5ce15f21c424d4c657a1b60d513841e90458cf67dfb
font_01_sfnt_off00010c53.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10C53 17072 bytes
SHA-256: 6eb850c8ca75689a46a2e9ee68bbe61e775b9544009d4d6122a0601bf7b527f5
font_02_sfnt_off0001393b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1393B 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1