Malicious PDF — malware analysis report

Static analysis result for SHA-256 01a668ca44354c93…

MALICIOUS

PDF

276.5 KB Created: 2022-04-03 20:27:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-06-01
MD5: 346bcea8df6f3a40c3532e1451a1de46 SHA-1: ad5decd413aaa62006c87f7909062edb20c09e7f SHA-256: 01a668ca44354c93a7518eea6fe8d14153f9a921d7f03ece1c80f0f15ce5623f
144 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.7877

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://colod.co.za/XSRYdR1H?utm_term=color%3A+a+course+in+mastering+the+art+of+mixing+colors PDF link annotation
    • http://www.majorisinvestimentos.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16224bec8259f5---79503404656.pdfIn PDF document text
    • http://oosterkerkhoorn.nl/UserFiles/files/kogefamidilu.pdfIn PDF document text
    • http://valleytechltd.com/assets/ckeditor/kcfinder/upload/files/98097711210.pdfIn PDF document text
    • https://nuttydog.hu/ckfinder/userfiles/files/687912845.pdfIn PDF document text
    • http://emanuelarombiarchitetto.eu/userfiles/files/70166280744.pdfIn PDF document text
    • http://erdelyironkbutor.hu/admin/kcfinder/upload/files/riwagetemizitaduwe.pdfIn PDF document text
    • https://lrsdev.com/userfiles/file/viluvafenezejuporiwijon.pdfIn PDF document text
    • https://immsac.pe/sgi_userfiles/userfiles/files/zibexoko.pdfIn PDF document text
    • https://vidaleve.ind.br/ckfinder/userfiles/files/15919288001.pdfIn PDF document text
    • http://mastera-mix.ru/ckfinder/userfiles/files/pegesamemesirekaviped.pdfIn PDF document text
    • http://robwalker.net/fckupload/file/86718258888.pdfIn PDF document text
    • http://www.atad.ae/emanager/assets/ckeditor/plugins/kcfinder/upload/files/72691429533.pdfIn PDF document text
    • http://kptar.com.br/kcfinder/upload/files/pezufivuzaku.pdfIn PDF document text
    • https://jasmijnbloemengroen.nl/userfiles/file/21580489625.pdfIn PDF document text
    • http://machinesupplier.cn/data/product/file/2022225_19204_222.pdfIn PDF document text
    • http://vdi.vn/userfiles/file/80948307006.pdfIn PDF document text
    • http://bothtree.com/userfiles/file/xavebeferivupit.pdfIn PDF document text
    • https://prolinenergy.com/Admin/plugins/ckeditor/kcfinder/upload/files/litugipuv.pdfIn PDF document text
    • https://snowcat.pl/admin/ckfinder/userfiles/files/larevejabeve.pdfIn PDF document text
    • http://sun-apartments.pl/data/pages/50792494589.pdfIn PDF document text
    • http://tapdoannamduoc.com/img-tvdl/files/16902537806.pdfIn PDF document text
    • https://liad-alger.fr/admin/style/js/edit/kcfinder/..%5Cimages%5Ccontenue/files/10861889726.pdfIn PDF document text
    • http://baheth24aqari.com/ckfinder/userfiles/files/mokiloxumikitine.pdfIn PDF document text
    • http://artgraf24.pl/userfiles/file/desexinetitu.pdfIn PDF document text
    • http://www.majbrno.cz/uploads/files/11278278268.pdfIn PDF document text
    • http://p-energo.ru/content/file/xuwepifiwapeb.pdfIn PDF document text
    • http://forsheda.se/admin/kcfinder/upload/files/40139033149.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0003e38a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3E38A 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off0003fba1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3FBA1 11132 bytes
SHA-256: c2e822c653150b96cf8862ae7a8c4d1f12fb46f76a52d73c5f4fb3037e7740b8
font_02_sfnt_off0004155f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4155F 17340 bytes
SHA-256: 7ba04921a139bc59fc2da5ad536e2517f49067dc215a4aaa3e41799e7f08784a