Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2c0e0671a27bf43…

MALICIOUS

PDF

16.6 KB Created: 2020-11-09 16:34:09 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-05
MD5: f56bd08b66ce6207e79e6d9b418ee533 SHA-1: 64797245b7ee153ea61e41a9c63dbbd4490dbc92 SHA-256: c2c0e0671a27bf43e69d30dde6454fab70ae476af5bbb82dcffc9ca226c05d45
74 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains heuristics indicating it is a lure for free downloads, redirecting users to a malicious URL. The primary malicious URL identified is https://traffset.ru/aws?keyword=the+design+of+everyday+things+pdf. While no scripts were extracted, the PDF structure and embedded links suggest a phishing attempt to trick users into downloading potentially malicious files.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9981

Heuristics 3

  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/aws?keyword=the+design+of+everyday+things+pdf PDF link annotation
    • https://dinomorozowi.weebly.com/uploads/1/3/4/6/134610364/fibegatum.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4368976/normal_5f994d12dcc72.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367305/normal_5f98705f21845.pdfIn PDF document text
    • https://xuvakaxatal.weebly.com/uploads/1/3/1/0/131070170/7a62390.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367633/normal_5f8c02bd2bea4.pdfIn PDF document text
    • https://repemigikaji.weebly.com/uploads/1/3/4/6/134608024/dd15cf68c.pdfIn PDF document text
    • https://s3.amazonaws.com/tosevud/voriw.pdfIn PDF document text
    • https://s3.amazonaws.com/felasorarabipis/materiales_dentales_propiedades_y_manipulacion_craig.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ed1bda44-91a9-42ac-ab81-40c461a3d437/mosudezadotorup.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/56fb07fd-7864-46a5-87b6-3c2d14124afd/instagram_porn_tags.pdfIn PDF document text
    • https://s3.amazonaws.com/tanikanaw/66935844284.pdfIn PDF document text
    • https://s3.amazonaws.com/purufiz/53978331207.pdfIn PDF document text
    • https://s3.amazonaws.com/jiguwuzobozobaz/free_download_game_killer_apk_full_version_for_android.pdfIn PDF document text