Malicious PDF — malware analysis report

Static analysis result for SHA-256 faed433b82d74d11…

MALICIOUS

PDF

83.1 KB Created: 2021-03-16 03:22:58 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-04
MD5: 61684be6da88653ce389b5877da48224 SHA-1: 11d4d6ea76a96bcada4644a064ca4e3b47623e22 SHA-256: faed433b82d74d118d88a6db23228ae3276398d6754e84cc34f22c8d03b9c36a
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file is identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It functions as a link farm, directing users to numerous external URLs, including suspicious domains like kuzutuzo.ru and shtancircul.site. The document body, though heavily obfuscated, suggests a deceptive lure related to "Neo freudians pdf". No scripts were extracted, but the presence of many external links points to a phishing or redirection scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9954

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/wix?keyword=neo+freudians+pdf PDF link annotation
    • https://s3.amazonaws.com/zibenoroduzuw/call_of_duty_mobile_game_size.pdfIn PDF document text
    • https://cdn.sqhk.co/sevijeruba/e3U7eP8/tejopiwi.pdfIn PDF document text
    • http://shtancircul.site/sitebawimubaniduzojubm8hky.pdfIn PDF document text
    • http://goods-amzon.com/how_to_reset_a_delphi_xm_radioh990i.pdfIn PDF document text
    • http://foxiduwanati.mygamesonline.org/download_novel_best_seller_2020.pdfIn PDF document text
    • https://s3.amazonaws.com/taturi/kusugudip.pdfIn PDF document text
    • http://blankid.ru/aplikasi_genetic_calculator_lovebirdjrjuo.pdfIn PDF document text
    • http://ergors.space/xitejiretfs6ln.pdfIn PDF document text
    • https://cdn.sqhk.co/tiwefuxab/pGjjjje/jinetarutaxilusujosido.pdfIn PDF document text
    • http://leadtop.co/how_much_does_enterprise_charge_to_rent_a_cargo_vanpzrfn.pdfIn PDF document text
    • https://cdn.sqhk.co/pazaxefuma/hdBjeBo/mezatifotibakamitaxem.pdfIn PDF document text
    • http://foxilajat.sportsontheweb.net/wenujovitif.pdfIn PDF document text
    • https://s3.amazonaws.com/gapivegek/vusozatiroguwek.pdfIn PDF document text
    • https://cdn.sqhk.co/votojuxosaf/6RIO9i5/song_pop_2_hacked_apk.pdfIn PDF document text
    • https://cdn.sqhk.co/jefigujaxev/gigc0hb/game_mod_big_bang_evolution.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://38f9ccf9-db33-4582-994d-0ea518e52d38.filesusr.com/ugd/368de4_dbc77d03ff4441b089a0bd4627340e8e.pdf?index=trueIn PDF document text
    • https://9387bd13-3746-4408-b474-2867f26e464d.filesusr.com/ugd/ace02d_c13fd09053a24f5eb4bc913c19eb0c72.pdf?index=trueIn PDF document text
    • https://46d16763-6c5f-4e19-aa2c-3f4071fcbec2.filesusr.com/ugd/26f730_2e0fc632064b4efc97ff4eccd17fd7b4.pdf?index=trueIn PDF document text
    • https://f45985d3-969e-4a4b-a16b-f92b7c881388.filesusr.com/ugd/20da2d_efd7e662134d4a049e83cb1f6cdc7655.pdf?index=trueIn PDF document text
    • https://3df06c22-1e8a-4082-8cc2-a0fdc0609706.filesusr.com/ugd/d86e81_4347d3d7d2294463a580f85fc6c8b483.pdf?index=trueIn PDF document text
    • https://8767aa75-4bd5-48c0-94ca-24e983238001.filesusr.com/ugd/debdc1_769a6259c6bc4a51bad6746e9a8756e8.pdf?index=trueIn PDF document text
    • https://34e223d5-b18a-4f89-96b3-7c58aa965d90.filesusr.com/ugd/440e29_5bcaae9b58254d399983b0131fa9c435.pdf?index=trueIn PDF document text
    • https://2d130471-2a64-48ba-87cf-8f1e86c6acad.filesusr.com/ugd/9c43ec_7f9970e981ff465988b1ffa8443077b6.pdf?index=trueIn PDF document text
    • http://jabodegodonirad.atwebpages.com/jamigelokubutilewakes.pdfIn PDF document text
    • http://rijemow.onlinewebshop.net/wajalulezafakuri.pdfIn PDF document text
    • https://4b5f4e46-8b81-4257-bf39-61fc08ba57b0.filesusr.com/ugd/7ea8bb_0b87595a9f1c4257a87dff52bcf24362.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fc60.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFC60 4776 bytes
SHA-256: ab394e521d5cd16f6b115bc88b1dc30ad719739706fdf6c0cde753dadae55431
font_01_sfnt_off00010ca5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10CA5 10652 bytes
SHA-256: 61d258fdbaba3093a04aa2a1d1eae1f3fc7166ba1472265a78f4b2761fc5e719
font_02_sfnt_off000130cf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x130CF 4324 bytes
SHA-256: b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c