Malicious PDF — malware analysis report

Static analysis result for SHA-256 116d9fb4bf76a3f7…

MALICIOUS

PDF

317.5 KB Created: 2022-04-14 19:17:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-06-05
MD5: ea0db1699ec4c9e8495079f31c5d7abb SHA-1: 1676cd52d09e0566e2fda5cfbf33a9e0d8e94237 SHA-256: 116d9fb4bf76a3f7395a46ad2081b6a298e4eeccb633fc0a0e72b86a6b3b1454
152 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.7334

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lazav.co.za/XSRYdR1H?utm_term=accounting+process+flowchart+template PDF link annotation
    • https://vida.posilatko.cz/files/wswg/files/xadewixesogipuzupop.pdfIn PDF document text
    • http://md-servicios.com/userfiles/file/jovozupu.pdfIn PDF document text
    • https://mizipajosufajod.weebly.com/uploads/1/3/4/0/134040675/kujilane.pdfIn PDF document text
    • https://safodejinuvi.weebly.com/uploads/1/3/4/7/134753113/6481211.pdfIn PDF document text
    • https://besusawoses.weebly.com/uploads/1/3/5/3/135318815/vudem_pekidusu_wevumafof_gizetaduk.pdfIn PDF document text
    • https://www.houseofwax.cz/kcfinder/upload/files/xadetejotuzum.pdfIn PDF document text
    • http://creaorganization.com/depo/sayfaresim/file/zexodiwenapefokefig.pdfIn PDF document text
    • https://puvedevedumu.weebly.com/uploads/1/3/1/4/131406841/3389947.pdfIn PDF document text
    • https://przyklejki.pl/userfiles/60480350971.pdfIn PDF document text
    • https://mmoxx.mn/userfiles/files/suxoredajanusomugoru.pdfIn PDF document text
    • http://lltsg.com/uploadfile/file///2022020808241455.pdfIn PDF document text
    • https://bipesulevawitod.weebly.com/uploads/1/3/1/4/131437914/najivabeluxarax-pekigadifid.pdfIn PDF document text
    • http://travelsolutions.co/ckeditor/kcfinder/upload/files/74840466511.pdfIn PDF document text
    • http://hadjtaharsteel.com/app/webroot/js/kcfinder/upload/files/miwapirejajanedubevez.pdfIn PDF document text
    • http://careerhack.net/wp-content/plugins/formcraft/file-upload/server/content/files/162193f978da23---35657064793.pdfIn PDF document text
    • https://wekenatiwajeko.weebly.com/uploads/1/3/7/5/137508738/vetuzigu.pdfIn PDF document text
    • http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/16254b5b62d71f---21577130577.pdfIn PDF document text
    • https://ichapps.com/ichapps/ckeditor-ckfinder-integration/uploads/files/94893757630.pdfIn PDF document text
    • https://napowokomedisuf.weebly.com/uploads/1/3/4/3/134379523/giranekexovunewikize.pdfIn PDF document text
    • http://vwtint.com/userData/board/file/11733646701.pdfIn PDF document text
    • http://gursakaryahukuk.com/images/file/70126637320.pdfIn PDF document text
    • https://tulewuzawiri.weebly.com/uploads/1/4/1/3/141323361/denokor.pdfIn PDF document text
    • https://kegazesawatodo.weebly.com/uploads/1/3/4/3/134378031/725e539cc.pdfIn PDF document text
    • https://liberiloro.weebly.com/uploads/1/3/4/5/134589576/be9465e8e.pdfIn PDF document text
    • https://dakawomafi.weebly.com/uploads/1/3/5/9/135959339/af47d3c3fded021.pdfIn PDF document text
    • https://ceb.lk/assets/js/kcfinder/upload/files/sidujov.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0004899a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4899A 16788 bytes
SHA-256: 675f4d244736efcefa7de27132c016e3cd06274e68470a684c0b0b7c57115aec
font_01_sfnt_off0004b4dc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4B4DC 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off0004ccf3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4CCF3 11096 bytes
SHA-256: c8b3f3eb5a5b8a0600f4324ee7ec1690e9d4138d93187ebe76744340844496bb