Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d39c2310be9b4ec…

MALICIOUS

PDF

90.7 KB Created: 2021-08-16 00:03:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-06-14
MD5: 2e7a4d4d47184f244f96d31fd280ea3e SHA-1: 1097bb272a0abc2978efb1d8efb5b2efacdc6942 SHA-256: 0d39c2310be9b4ec99db6b2287b20b6559f4c1736a30bf03d84b897fb3d801a9
156 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9973

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://erinmillssmilesdentistry.com/wp-content/plugins/super-forms/uploads/php/files/v1aocbkt4jg3r6faqit9vvll07/77179086763.pdf In PDF document text
    • http://boxerdapolenta.com/cmsimple/images/file/logijoxovupomuj.pdfIn PDF document text
    • http://sevimticaret.net/userfiles/file/1811602678.pdfIn PDF document text
    • https://tonitomov.com/picture/file/11067552693.pdfIn PDF document text
    • https://editora-arara-azul.com.br/site/admin/ckfinder/userfiles/files/7092633953.pdfIn PDF document text
    • https://christianboudreau.com/wp-content/plugins/formcraft/file-upload/server/content/files/160aa6853bca88---68620867781.pdfIn PDF document text
    • http://akbmodel.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607e910b4c1d1---fosubiladuzumovexaxoxar.pdfIn PDF document text
    • https://heatingboiler.ca/fck_upload/file/wefozatakusofugov.pdfIn PDF document text
    • http://mid-europe-ex.com/images/blog//file/63738207990.pdfIn PDF document text
    • http://stopasbestos.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160893fa9edc9f---wimefafivimapepoza.pdfIn PDF document text
    • https://www.potterycommercials.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1607208aac1e5e---taguvinonetowo.pdfIn PDF document text
    • http://fritz-fahrlaender.ch/download/46966425147.pdfIn PDF document text
    • http://www.sg-callenberg.de/wp-content/plugins/formcraft/file-upload/server/content/files/160b21f85c99dc---wifavenosurixudopifesor.pdfIn PDF document text
    • http://www.heksan.com.pl/file/rituzafisoru.pdfIn PDF document text
    • http://www.cuerpomenteyespiritu.es/wp-content/plugins/formcraft/file-upload/server/content/files/160c2b724a0a9a---30962156413.pdfIn PDF document text
    • http://stavebnevyrobky.sk/www/upload/files/18928271684.pdfIn PDF document text
    • https://saint-florentin.charcutier-traiteur.fr/ckfinder/userfiles/files/21095861966.pdfIn PDF document text
    • https://argekaucuk.com/nbg/upload/files/71984833764.pdfIn PDF document text
    • http://meble-tk.pl/userfiles/file/38255289613.pdfIn PDF document text
    • https://adiwirawanbali.com/wp-content/plugins/super-forms/uploads/php/files/74360949a8d880751e5d5077715474da/dupovalokufej.pdfIn PDF document text
    • http://kmkonsult.cz/userfiles/file/bekenoxenevu.pdfIn PDF document text
    • http://deurwater.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a3704ba0940---fonapajinani.pdfIn PDF document text
    • http://www.gametimecatering.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609906de65730---8658348630.pdfIn PDF document text
    • https://harpethvalleyhealth.com/wp-content/plugins/super-forms/uploads/php/files/0f57f15a8cc041f96add1ebff0fea7fa/7896658813.pdfIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/BvfzZFkJO3s/uplcv?utm_term=what+channels+are+on+live+net+tvPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010278.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10278 16564 bytes
SHA-256: eb966d112e1ed3b785a8b976a5eff48a10d3b46281a7273f6db81ae29e019033
font_01_sfnt_off00012d9e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12D9E 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off000145b5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x145B5 10384 bytes
SHA-256: bf9d9b7db83f1487a6c79ecc1c3c4ac3c7edba8616e8310d519215a73c79fc6a