Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0cb60c99c00a3ef…

MALICIOUS

PDF

74.8 KB Created: 2021-03-22 09:50:10 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-04
MD5: 91d8eed760ee3e3f3ec46e70f3341ee0 SHA-1: e33ef2c83a29a763211d749a461c13edd8e519f8 SHA-256: e0cb60c99c00a3ef16900808abf1500c13d8b9bd850d1212f26a80cfb0701b10
176 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The file was detected as malicious by ClamAV and an ML classifier, exhibiting characteristics of an advance-fee scam lure. It contains an external URI pointing to a redirector designed for SEO manipulation, likely to trick users into downloading malicious content. The presence of PDF-specific heuristics and the overall structure suggest an attempt to exploit PDF viewers.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/award?keyword=java+basic+programs+examples+pdf+free+download PDF link annotation
    • https://cdn.sqhk.co/zobelekivix/TmiehdQ/titan_quest_switch_update.pdfIn PDF document text
    • https://cdn.sqhk.co/kufejeni/9ZbhbZf/oklahoma_state_football_roster_2013.pdfIn PDF document text
    • https://cdn.sqhk.co/kominepoli/bjjgeib/bow_weapons_destiny_2_without_forsaken.pdfIn PDF document text
    • https://s3.amazonaws.com/tofizo/vegas_pro_crack_version.pdfIn PDF document text
    • https://cdn.sqhk.co/gulaxemetila/gtFieiF/tunebebinoxejobarozu.pdfIn PDF document text
    • https://cdn.sqhk.co/lutotilivik/Ehjjghb/42090274208.pdfIn PDF document text
    • https://cdn.sqhk.co/wuvukidovime/zsIggid/rotuloler.pdfIn PDF document text
    • https://cdn.sqhk.co/guviterolovu/XsdviaO/lewazuzawutulub.pdfIn PDF document text
    • https://cdn.sqhk.co/tawibonikigo/heBjehb/revolutionary_iran_michael_axworthy.pdfIn PDF document text
    • https://s3.amazonaws.com/babetafaperaxov/how_to_get_osha_forklift_certification.pdfIn PDF document text
    • http://xinuvaro.sportsontheweb.net/synonyms_and_antonyms_with_bangla_meaning.pdfIn PDF document text
    • https://cdn.sqhk.co/libuzewis/cigiegd/flying_ants_in_house_after_rain.pdfIn PDF document text
    • https://s3.amazonaws.com/niwotipugonuvoz/adda_movie_lo_songs.pdfIn PDF document text
    • https://s3.amazonaws.com/jenagubadopi/crystal_maiden_item_build_guide_dota_2.pdfIn PDF document text
    • https://s3.amazonaws.com/fopalew/dunixewajabog.pdfIn PDF document text
    • http://java67.comIfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/f0256821-dc29-4e1b-a1de-2cd00b2a8c04/wuvijinadimu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0dc4fb7b-e3e9-49d0-98d9-4212c5e34f69/37043472871.pdfIn PDF document text
    • http://bebojivim.myartsonline.com/binocular_vision_disorder.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/53cbfd91-4df6-4cf5-b64f-fd1f4a98af35/zagidapegezefugilavifek.pdfIn PDF document text
    • http://lamupimifuban.onlinewebshop.net/data_science_and_big_data_analytics_wiley.pdfIn PDF document text
    • http://javarevisited.blogspot.comIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e54e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE54E 5824 bytes
SHA-256: 59748576cebcd2c52970b54571a43ba2b223ac1430c8735d4b44ebbbc7e3f1d5
font_01_sfnt_off0000f922.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF922 10648 bytes
SHA-256: 8d773b5d75b95714e0a4f695f1e2a90bdbea710ba66ba6efd239e28114f7230f