Malicious PDF — malware analysis report

Static analysis result for SHA-256 03eb492622ad5790…

MALICIOUS

PDF

331.9 KB Created: 2022-04-10 00:45:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-10
MD5: bddc720763610d0b275e1a843d5f5c12 SHA-1: 3c0dd9c92c2ec40d0ab753e741ab6d31e6b4aaf1 SHA-256: 03eb492622ad5790d5d84960785d8ea04ffb2e469899d1c10a10faf0002387c8
136 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.7583

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://rimulebomivek.weebly.com/uploads/1/4/1/2/141261028/xobabixibidu.pdf In PDF document text
    • https://zagumugapepari.weebly.com/uploads/1/3/1/6/131636872/wapivedu.pdfIn PDF document text
    • http://www.creativitaecomunicazione.it/js/lib/ckfinder/userfiles/files/labikexetumibid.pdfIn PDF document text
    • https://boxirerekejo.weebly.com/uploads/1/3/4/1/134108979/3432d1.pdfIn PDF document text
    • https://vadurevagide.weebly.com/uploads/1/3/3/9/133999829/vomogojep-wemov-nobekedonumep.pdfIn PDF document text
    • https://jugevenow.weebly.com/uploads/1/3/4/7/134736768/8fd47f.pdfIn PDF document text
    • http://klhb365.com/userfiles/file/art_16470409592045.pdfIn PDF document text
    • https://sodujamewo.weebly.com/uploads/1/3/4/7/134750465/2995018.pdfIn PDF document text
    • https://thietbibepnhahang.toanphatcorp.vn/media/files/79425928223.pdfIn PDF document text
    • https://roxracing.eu/userfiles/file/lunowusutamerebapabokonid.pdfIn PDF document text
    • https://toxofeleziwogiz.weebly.com/uploads/1/3/1/4/131406173/fajij.pdfIn PDF document text
    • http://apicn.net/upload/files/58642136188.pdfIn PDF document text
    • https://vonufire.weebly.com/uploads/1/3/4/5/134596457/2158551.pdfIn PDF document text
    • http://www.rannatennis.ee/data/upfiles/files/forikozoxidipaxexabir.pdfIn PDF document text
    • https://eletvital.hu/uploads/files/31018904220.pdfIn PDF document text
    • https://vasoderavir.weebly.com/uploads/1/3/4/7/134728489/8652989.pdfIn PDF document text
    • http://alzinda.fr/ckeditor/kcfinder/upload/files/didegidezuj.pdfIn PDF document text
    • https://zusadadej.weebly.com/uploads/1/3/4/8/134856209/donofejivixesonipote.pdfIn PDF document text
    • http://paymentsbusiness.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1622067f9bc526---65214095096.pdfIn PDF document text
    • https://tumixivig.weebly.com/uploads/1/3/1/6/131636813/7901128.pdfIn PDF document text
    • https://roriwemako.weebly.com/uploads/1/3/4/5/134599113/724ca3c5b1627b6.pdfIn PDF document text
    • https://pasationtravellers.com/root/FCKeditor/file/jesemibimijugek.pdfIn PDF document text
    • https://wojisixid.weebly.com/uploads/1/3/4/3/134359836/sanebefamun.pdfIn PDF document text
    • https://nujokolove.weebly.com/uploads/1/3/0/8/130874035/5232825.pdfIn PDF document text
    • http://divapharma.com/uploaded/file/69324218565.pdfIn PDF document text
    • https://xelexezeni.weebly.com/uploads/1/3/0/7/130740222/64f62f35269586c.pdfIn PDF document text
    • http://stickers-moins-cher.com/userfiles/stickers-moins-cher.com/file/8464397985.pdfIn PDF document text
    • https://benubusu.weebly.com/uploads/1/3/4/5/134577078/nifiwosisivefisu.pdfIn PDF document text
    • https://colod.co.za/XSRYdR1H?utm_term=anvils+in+americaPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0004bc40.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0004bc40.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0004bc40.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4BC40 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off0004d457.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4D457 10220 bytes
SHA-256: 49eb9dc2e2aac96290c54027b741ca8de617fcaa9033052ebdf68d58ac7d9e74
font_02_sfnt_off0004eb38.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4EB38 20124 bytes
SHA-256: 3911644ecddeabaa722baf9eba40b0b810a11844c84d9309376c17c664e5a6a0