Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d3ae44703df60be…

MALICIOUS

PDF

493.0 KB Created: 2022-03-15 13:49:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-06-14
MD5: 0719445f08a8bf1abacc9f7149ab2de0 SHA-1: 88fa5c144a609116c57af3ea733ef65a266fe93a SHA-256: 0d3ae44703df60be1e8a67a30dfd3fa6542bf52bd59611b0615d1309cd406f2f
174 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF contains embedded JavaScript and multiple external links, including one pointing to a compromised WordPress upload directory. The presence of a PDF_SEO_UTM_REDIRECTOR_LINK heuristic indicates a lure for free downloads, likely a phishing or malware distribution tactic. The embedded JavaScript is likely used to facilitate the download and execution of a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5336

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lazav.co.za/XSRYdR1H?utm_term=adanga+maru+full+movie++kuttyweb PDF link annotation
    • https://gpagroup.in/wp-content/plugins/formcraft/file-upload/server/content/files/1622decaba824c---josej.pdfIn PDF document text
    • https://unovosti.tv/ckfinder/userfiles/files/25952737967.pdfIn PDF document text
    • https://www.3gimmobilier.com/kcfinder/upload/files/somaxodopajunajojakumij.pdfIn PDF document text
    • http://cohn-vossen.com/wp-content/plugins/formcraft/file-upload/server/content/files/161f8a36d671f3---nozufu.pdfIn PDF document text
    • http://tamezou.com/upload/ckfinder/files/95982810420.pdfIn PDF document text
    • http://www.naturhalles.fr/fckeditor/userfiles/file/xafamabekisot.pdfIn PDF document text
    • http://wetravels.com/kcfinder/upload/files/kipipafarawuvadi.pdfIn PDF document text
    • https://www.sgestrecho.es/wp-content/plugins/formcraft/file-upload/server/content/files/1620dfd606ae39---tidovugefusepofifotawaz.pdfIn PDF document text
    • https://member-amz-seller-system.de/wp-content/plugins/super-forms/uploads/php/files/5e80bfb2f8d2683a2e63a413acfbdedb/tireka.pdfIn PDF document text
    • http://www.propper-droppers.nl/files/file/10143569144.pdfIn PDF document text
    • https://webdatedepot.com/userfiles/file/53742257403.pdfIn PDF document text
    • http://coachoutletcanada.dansecyr.ca/pdf/file/laxabef.pdfIn PDF document text
    • http://vnos.vn/app/webroot/uploads/files/13229864460.pdfIn PDF document text
    • http://universityjournals.org/app/webroot/js/kcfinder/upload/files/15068847867.pdfIn PDF document text
    • https://michalheger.cz/soubory/files/nujezamad.pdfIn PDF document text
    • http://psn-monolit.ru/img_file/files/27376206265.pdfIn PDF document text
    • http://verkoop-je-wagen.be/wp-content/plugins/formcraft/file-upload/server/content/files/161ff361cbb337---16239932006.pdfIn PDF document text
    • http://kjphotocon.org/data/userfiles/files/73434697871.pdfIn PDF document text
    • https://laserhkt.com/admin/uploadfiles/file/veduwelixepedet.pdfIn PDF document text
    • https://marugame.hk/editor_upload/file/72910062687.pdfIn PDF document text
    • https://selectwifi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1620d77f85bfec---bilejezorebudu.pdfIn PDF document text
    • http://4seasonstours.in/userfiles/file/bates.pdfIn PDF document text
    • http://chaodontuonglai.vn/uploads/ck_upload/files/96321773238.pdfIn PDF document text
    • http://constructionone.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16226dd19781c1---87273568745.pdfIn PDF document text
    • http://teplo76.ru/uploads/file/98521306566.pdfIn PDF document text
    • http://thanhlamresort.vn/wp-content/plugins/formcraft/file-upload/server/content/files/16226bf17474a9---wajuseboxo.pdfIn PDF document text
    • https://www.trungtammaychieu.com/ad-min/js/libs/kcfinder/upload/files/22497770548.pdfIn PDF document text
    • https://www.notusweb.com.br/ckeditor/ckfinder/userfiles/files/63471568018.pdfIn PDF document text
    • http://www.platformliften.info/wp-content/plugins/formcraft/file-upload/server/content/files/1622008bd1e6d4---kipujinofe.pdfIn PDF document text
    • https://www.frontiermyanmar.com/sites/all/libraries/ckfinder/userfiles/files/mowoter.pdfIn PDF document text
    • http://hichipper.com/hichipper/uploadfile/file/2022030903542973499.pdfIn PDF document text
    • http://cmtdental.com/upload/ckimg/files/53886613710.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00073f5f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x73F5F 19680 bytes
SHA-256: 25186a3bf27a89030e78b2020d6de5b72d78f80381b9d15b2c0ef439323afaf0
font_01_sfnt_off000772c8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x772C8 11108 bytes
SHA-256: b2a0767545449fc4213a9894e4928cd6792c2162561601c21e337bde4db8520b
font_02_sfnt_off00078c86.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x78C86 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9