Malicious PDF — malware analysis report

Static analysis result for SHA-256 03e75aa5a517d911…

MALICIOUS

PDF

307.8 KB Created: 2022-02-08 04:52:49 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-10
MD5: 5ed93bd6f486e41d264044c3e85e3ccf SHA-1: 0d9c2605dcbbcaf92878631be7ef701b9dc2c322 SHA-256: 03e75aa5a517d911068b94be543e6365c4bd08503c1fa4ba8c31c23cf2b241b3
166 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.5268

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://colod.co.za/XSRYdR1H?utm_term=oblique+asymptotes+pdf PDF link annotation
    • https://subarini.sibiuimobiliare.ro/mm/file/lurawi.pdfIn PDF document text
    • http://churchontherockuk.org/home/churchontherock1/public_html/userfiles/files/jawekojegejajidavenegiju.pdfIn PDF document text
    • http://brixtontaxi.com/survey/userfiles/files/ladoni.pdfIn PDF document text
    • https://grancom.by/upload/docs/lejawa.pdfIn PDF document text
    • https://cicapersonel.com/upload/files/19097210487.pdfIn PDF document text
    • http://yousefmaktabi.com/ckfinder/userfiles/files/91707735379.pdfIn PDF document text
    • http://terwaarde.be/ckfinder/userfiles/files/71257634713.pdfIn PDF document text
    • http://sola-brothers.com/userfiles/file/kejinetemaxet.pdfIn PDF document text
    • http://xn--80akoseq9f.xn--p1ai/userfiles/file/49932166557.pdfIn PDF document text
    • http://ekogamma.pl/javascript/ckfinder/userfiles/files/zagipajuxepigafit.pdfIn PDF document text
    • http://www.timtransportes.com/home/wp-content/plugins/formcraft/file-upload/server/content/files/16198d8b3d93a4---53567518429.pdfIn PDF document text
    • http://marinaxaraes.com.br/ckfinder/userfiles/files/64992685136.pdfIn PDF document text
    • http://dabien.co.kr/wp-content/plugins/formcraft/file-upload/server/content/files/160e0861865537---92301070963.pdfIn PDF document text
    • https://webmanagement.exing.ro/images/file/kodelonupom.pdfIn PDF document text
    • https://eventaipei.com/upload/files/96279416149.pdfIn PDF document text
    • https://inchiriereelicopterromania.ro/wp-content/plugins/formcraft/file-upload/server/content/files/16164e38f63339---25314435278.pdfIn PDF document text
    • http://damutech.kz/upload/2021/09files/210913185226782788ggy97.pdfIn PDF document text
    • http://thcsducthang.pgdbactuliem.edu.vn/ckfinder/userfiles/files/55560554091.pdfIn PDF document text
    • http://tecksco.com/upload/files/vepusuzid.pdfIn PDF document text
    • https://jokerprod.net/userfiles/file/23714361642.pdfIn PDF document text
    • http://medeeatour.ro/mm/file/13423834956.pdfIn PDF document text
    • https://millersexpress.com/userfiles/file/danenonujipuguren.pdfIn PDF document text
    • https://ballestermultiservicios.com/wp-content/plugins/formcraft/file-upload/server/content/files/161bbe23cb0c9c---61651984898.pdfIn PDF document text
    • http://zcapitalcrm.com/app/webroot/uploads/files/tigukanikositusetin.pdfIn PDF document text
    • https://cashcruis.ru/wp-content/plugins/super-forms/uploads/php/files/0e8582fbc5ed39982c871e5f11775260/17662575306.pdfIn PDF document text
    • http://librojuridico.com/aym_images/files/nomuvasuwajisewam.pdfIn PDF document text
    • http://www.pavimentosyreformasferlu.es/ckfinder/userfiles/files/57238341838.pdfIn PDF document text
    • http://lungshingcentre.com/userfiles/86834292440.pdfIn PDF document text
    • https://noks.cz/wp-content/plugins/formcraft/file-upload/server/content/files/16201b05a56f61---51342076816.pdfIn PDF document text
    • http://www.mkfilm.it/ckeditor/kcfinder/upload/files/damezexifadir.pdfIn PDF document text
    • http://chronoflex-dz.com/app/webroot/assets/js/kcfinder/upload/files/83140167328.pdfIn PDF document text
    • https://linhquan-group.com/upload/ck/files/taranejun.pdfIn PDF document text
    • https://kuadrifoglio.it/upload/userfiles/files/22898065866.pdfIn PDF document text
    • http://csc025.com/userfiles/file/20211111030749_tvkgcs.pdfIn PDF document text
    • http://alphanaturehk.com/userfiles/file/zovizabakuxuvug.pdfIn PDF document text
    • https://bizdrive.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1/161543ec744de1---29354898669.pdfIn PDF document text
    • http://kondicionery-dolgoprudny.ru/upload_picture/file/tepevekinikusemezawako.pdfIn PDF document text
    • https://jmclimatizacionhvac.cl/images/subidas/file/9553333480.pdfIn PDF document text
    • https://franchisefarm.franchiseharbor.com/files/files/baresudi.pdfIn PDF document text
    • http://www.kidnuri.com/wp-content/plugins/formcraft/file-upload/server/content/files/160fe46269fcfe---vumitoje.pdfIn PDF document text
    • http://bukhatirhomes.com/userfiles/file/jitikitilepejemidates.pdfIn PDF document text
    • http://urparitet.ru/admin/ckfinder/userfiles/files/jepiviva.pdfIn PDF document text
    • https://confidence-ist.com/ckfinder/userfiles/files/fogojoxobajiritoser.pdfIn PDF document text
    • https://lixtech.com.tw/ckfinder/ckfiles/files/lazewarobibegudiwon.pdfIn PDF document text
    • https://ehilteknik.com/uploads/files/lowogawul.pdfIn PDF document text
    • https://swotin.com/wp-content/plugins/formcraft/file-upload/server/content/files/161013200487e9---zidavapined.pdfIn PDF document text
    • http://christopherdallo.com/file/nupojalugiw.pdfIn PDF document text
    • http://shop-cartuning.com/userfiles/file/23496250324.pdfIn PDF document text
    • http://studiolorenzoni.eu/userfiles/files/kuputolugatajazojep.pdfIn PDF document text
    +8 more URL(s)

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00043ef5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x43EF5 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_01_sfnt_off00045612.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x45612 21428 bytes
SHA-256: 0bfda567d7b0b259f252847dc561202050fd5ee7c603f8d96cf92f6e2dd28258
font_02_sfnt_off00048edc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x48EDC 16224 bytes
SHA-256: 919f1bc367624d721b2fb31ab12125a2b73dd255637d65187c7543b9c3013291
font_03_sfnt_off0004a4c1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4A4C1 10980 bytes
SHA-256: 6a948badaf352359be5e73353582a92df942b78125562250b9a7f9cb0e053a6d