Malicious PDF — malware analysis report

Static analysis result for SHA-256 cc4b52e9bebd2d40…

MALICIOUS

PDF

91.6 KB Created: 2021-03-19 07:34:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-04
MD5: 9089987379d231c91514b33666a6b386 SHA-1: 01df576515c7f1d9c7af378fdc26fa262fdaeffd SHA-256: cc4b52e9bebd2d4027eaf3929c1213f855520dbd031ecf0de0e68a2235fd13fc
194 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file is identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan payload. It contains a large number of external links, many hosted on disposable domains, suggesting a link farm designed to redirect users to malicious content. The presence of a 'download button' heuristic further supports a lure-based attack pattern. While no scripts were explicitly extracted, the PDF structure and link farm indicate an attempt to deliver a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/123?utm_term=kerala+psc+malayalam+questions+and+answers PDF link annotation
    • https://cdn.sqhk.co/fopeziriga/gjhgchc/hero_xtreme_bike_price_in_bd.pdfIn PDF document text
    • https://cdn.sqhk.co/livatunozasu/o21eUgd/famous_sculpture_artists_modern.pdfIn PDF document text
    • https://rilavowa.weebly.com/uploads/1/3/2/7/132740415/0e0fa293.pdfIn PDF document text
    • https://cdn.sqhk.co/rapawomo/ihIjhii/33274480754.pdfIn PDF document text
    • http://kuviruvada.getenjoyment.net/aprender_ingles_intermedio.pdfIn PDF document text
    • http://tixesikixux.mygamesonline.org/27632029672.pdfIn PDF document text
    • https://cdn.sqhk.co/padasagam/Tdaheie/933091326.pdfIn PDF document text
    • https://luboguti.weebly.com/uploads/1/3/0/7/130739177/sutip.pdfIn PDF document text
    • http://dofuluxaruze.22web.org/classic_wow_leveling_guide_mage.pdfIn PDF document text
    • https://lamuwibosuzo.weebly.com/uploads/1/3/1/0/131071033/3134132ce.pdfIn PDF document text
    • https://cdn.sqhk.co/tawunipufop/hdhclGP/halloween_costumes_2020_kids.pdfIn PDF document text
    • https://cdn.sqhk.co/seponidozit/Ehj8hhk/jozimifumibexifaperosej.pdfIn PDF document text
    • https://cdn.sqhk.co/dudofolejune/fgegcAy/hard_riddles_with_simple_answers_in_spanish.pdfIn PDF document text
    • https://cdn.sqhk.co/sodelaranu/hzgdGDn/womens_tank_tops_jumpers.pdfIn PDF document text
    • https://cdn.sqhk.co/miviluwulux/ijhchdZ/17918946597.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
    • http://smc.org.inhttp://smc.org.inIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • http://venakato.epizy.com/mutexaleputulodapevose.pdfIn PDF document text
    • http://kinuvafarugabob.rf.gd/digital_electronics_book_free.pdfIn PDF document text
    • http://vaxomuterok.epizy.com/reconciliation_action_plan_template_for_early_childhood.pdfIn PDF document text
    • http://tuxabatadifu.onlinewebshop.net/479004623.pdfIn PDF document text
    • http://sitotozip.rf.gd/vcenter_server_appliance_install_guide.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • https://gitlab.com/smc/meera/blob/master/COPYINGIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000104c6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x104C6 5392 bytes
SHA-256: a0655f9afafc02252862c8c36b720dcdaa131718ef4331fa50efb57adb850c5e
font_01_sfnt_off00011706.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11706 5144 bytes
SHA-256: e3574e5929501f862ad14770809f01cf857429ea0a8864dcdeeecc285e917e17
font_02_sfnt_off000129f9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x129F9 11340 bytes
SHA-256: 2365a14678c44d2b3883a58d6072c7d32c5f0e479d7d11a148875a664457c112
font_03_sfnt_off0001509f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1509F 4324 bytes
SHA-256: 4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3