Malicious PDF — malware analysis report

Static analysis result for SHA-256 f04d717630f7aaed…

MALICIOUS

PDF

75.1 KB Created: 2021-04-05 18:09:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-04
MD5: 69792545d9ae419cdb6c032b2c7279c5 SHA-1: 51afbb21c10bdfb6d62d17796c3466111943560a SHA-256: f04d717630f7aaedd041b77c7cce7702f1b501045d8f2066828c7e452eacbdad
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which point to SEO-optimized redirector URLs. One prominent URL, 'https://druttle.ru/wix?keyword=topsail+basketball+association+hampstead+nc', is presented as a lure related to a specific search query. The presence of a large number of external links and the ML classifier's high confidence score indicate a malicious intent, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=topsail+basketball+association+hampstead+nc PDF link annotation
    • https://s3.amazonaws.com/nabifovu/8202814559.pdfIn PDF document text
    • https://s3.amazonaws.com/limepusotanal/6618248989.pdfIn PDF document text
    • https://s3.amazonaws.com/gonima/ordinal_numbers_activity_sheet.pdfIn PDF document text
    • https://s3.amazonaws.com/ruzaganog/wakiniwadutafofiratinas.pdfIn PDF document text
    • https://s3.amazonaws.com/xisakazelelinim/indoor_cycling_app_for_android.pdfIn PDF document text
    • http://gebikomuxe.getenjoyment.net/69939593413.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4402481/normal_6020b31e0c079.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417315/normal_6034de0fc2f03.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4375503/normal_6007a9a863ea1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4500446/normal_60267f13225b5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4421474/normal_602239b5a4a26.pdfIn PDF document text
    • https://s3.amazonaws.com/nasitevu/youre_the_parent_youre_in_charge_meme.pdfIn PDF document text
    • https://s3.amazonaws.com/tafogusegabomu/77852908443.pdfIn PDF document text
    • https://s3.amazonaws.com/gozifep/bendy_and_the_ink_machine_apk_pure.pdfIn PDF document text
    • https://s3.amazonaws.com/makumapikeze/atonal_music_theory.pdfIn PDF document text
    • http://zezasarasojid.mywebcommunity.org/all_the_kings_horses_line_dance.pdfIn PDF document text
    • https://s3.amazonaws.com/jobavo/bee_movie_app_latest_version.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://pixafur.atwebpages.com/lenegoxagumo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ba4a8967-2be0-4b0c-8b98-62779406425b/lifuvowoposesiviperoruv.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4f523958-6b6f-40ea-bd1a-2e8b22acadda/zirifaxiwoza.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/12d7ca77-4e0f-4c2f-8030-04dfbaf45004/canon_eos_rebel_t5_weight.pdfIn PDF document text
    • https://03386fec-e341-46be-bf9f-2f2bd19f9bfe.filesusr.com/ugd/bf57b5_d809a1ff39434097a21abd8cfd179edb.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/774c9872-1da3-4abf-8235-9c6eae0a8842/84458397095.pdfIn PDF document text
    • https://f579be4a-c2ec-451d-94ee-532237c06880.filesusr.com/ugd/9f6a24_217f1093c0fc4379af37a76bde5e3209.pdf?index=trueIn PDF document text
    • https://7f3356c1-ec1f-498a-9d41-5b36c14d87b7.filesusr.com/ugd/98d33d_1e961e80e49f4fb8bc57b3779232ec4b.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dbd4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDBD4 5372 bytes
SHA-256: 91dd91fb2a6a8676f0f57e08022be109a65e9986a0de090bb0cfe2cf7a64e462
font_01_sfnt_off0000eddc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEDDC 2640 bytes
SHA-256: 0bffa03402480dacacf2561e0d274fe52505f17b15825b9619e184bb6a0f3cbf
font_02_sfnt_off0000f96f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF96F 11104 bytes
SHA-256: 2419e1a2a8335709dfd886f74f6b0009bf436860243b0cc8c6ae500ae363b32a