Malicious PDF — malware analysis report

Static analysis result for SHA-256 f87005c092a36f9d…

MALICIOUS

PDF

89.8 KB Created: 2021-12-08 14:00:02 +03:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2026-06-16
MD5: bc75d78ec60fac13250ea9a8357f4da3 SHA-1: c6c974ed5befecd10abd077fc36700291fa3c215 SHA-256: f87005c092a36f9d2d9c192b4f65c7ce3f6566bac88c80d41226eee5e3dc014e
67 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0240

Heuristics 5

  • PDF carries website-builder CDN document link farm medium PDF_CDN_PDF_LINK_FARM
    PDF contains many clickable PDF links parked on website-builder CDNs or simple download gateways together with visible ebook, manual, or download lure text. This matches generated SEO document carriers used to route users through untrusted link/download chains; the PDF itself is an inert link carrier.
  • PDF links to disposable redirector campaign host medium PDF_DISPOSABLE_REDIRECTOR_CAMPAIGN
    PDF's outbound link points to a throwaway redirector domain that recurs as the sole redirect across a large family of otherwise unrelated spam PDFs (movie-piracy, affiliate, and viral-link lures). These domains appear on no reputable list and exist only to funnel openers into malvertising / scam / download chains.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://getpdf.pw/book?res=strik&isbn=9780500292822&kwd=The%20American%20Dream%20:%20pop%20to%20the%20present PDF link annotation
    • https://static.s123-cdn-static-a.com/uploads/4659931/normal_61af68bd30e95.pdfIn PDF document text
    • https://files8.webydo.com/9589102/UploadedFiles/A2C8E33C-A7EF-5B82-F0EE-F8D85CDCE004.pdfIn PDF document text
    • https://static.s123-cdn-static-d.com/uploads/4660103/normal_61afc6c2240a5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4659925/normal_61af9f1982284.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn extracted file (stream_006_off000109b5.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off000109b5.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x109B5 21940 bytes
SHA-256: 871e7aaf17dd674645c4ada0a689c11c25262695995270baa07d60edd1624ae9
font_01_sfnt_off00013ce5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13CE5 18744 bytes
SHA-256: 01b73bd24048cf8692f19a136d0d9701049410c0ee343e5fc96fc3fa4c69b95e