Malicious PDF — malware analysis report

Static analysis result for SHA-256 116ef25d096ac1fe…

MALICIOUS

PDF

324.8 KB Created: 2022-02-07 19:00:17 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-06-05
MD5: 9141ee1d28cbbf11a06e3f21e6c7ebfa SHA-1: be0eb26859b2df4ef017d83948d61fa9d1f99472 SHA-256: 116ef25d096ac1fe8dccb9e357ea117dbc59063f1c1e36bc3390acc88afd6edb
184 Risk Score

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4431

Heuristics 8

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://loheb.co.za/XSRYdR1H?utm_term=ulala+idle+adventure+guide+temper PDF link annotation
    • http://jrpst.pl/userfiles/file/mabuweketajipijipufoj.pdfIn PDF document text
    • https://www.insideaccess.lk/assets/js/kcfinder/upload/files/5548036881.pdfIn PDF document text
    • https://zlato-stribro-investice.com/upload/files/vopivuzuxowub.pdfIn PDF document text
    • https://www.orthomaxindia.net/admin/kcfinder/upload/files/36090586157.pdfIn PDF document text
    • https://www.denisonlandscaping.com/wp-content/plugins/formcraft/file-upload/server/content/files/1616d49ecc66d5---48457461700.pdfIn PDF document text
    • https://pacientes.quiroser.com/UserFilesQUI/file/51751665522.pdfIn PDF document text
    • http://www.radioemka.com/wp-content/plugins/formcraft/file-upload/server/content/files/1618fa358165ee---dozalisi.pdfIn PDF document text
    • https://masterok-kovka.ru/wp-content/plugins/super-forms/uploads/php/files/8ae18fad67b56e9139c1834870a896ba/netubosalepoduguxuwow.pdfIn PDF document text
    • https://steyr-mannlicher.hu/admin/kcfinder/upload/files/kinez.pdfIn PDF document text
    • http://gemaeldeundobjekte.de/uploads/files/92051852773.pdfIn PDF document text
    • https://boucherienabli.com/uploads/FCK_files/file/nexedexepifojurexizimepox.pdfIn PDF document text
    • http://diamantina-joaillerie.com/ckfinder/userfiles/files/xinavixava.pdfIn PDF document text
    • https://www.bbmnetlicitacoes.com.br/cms/ckfinder/upload/files/galipasinibukujupafit.pdfIn PDF document text
    • http://studioingtassinari.eu/userfiles/files/bibuxoguxamulimali.pdfIn PDF document text
    • https://cornerstonelaw.eu/userfiles/file/21250334106.pdfIn PDF document text
    • http://embeddedhr.com/ckfinder/userfiles/files/kegovinidofekerov.pdfIn PDF document text
    • http://cambresisemploi.fr/ckfinder/userfiles/files/17111737907.pdfIn PDF document text
    • http://robvancampen.nl/userfiles/file/50615870538.pdfIn PDF document text
    • https://aarhuskortet.dk/images/file/43663743630.pdfIn PDF document text
    • http://erodiertechnik-wenzel.de/userfiles/file/23583176965.pdfIn PDF document text
    • https://lisalisa.ru/upload/files/jazagoxinapuv.pdfIn PDF document text
    • https://tkaniny-svitap.cz/kcfinder/upload/files/13086549563.pdfIn PDF document text
    • http://ropesadventure.com/d/files/defanexosamolejubetibajo.pdfIn PDF document text
    • http://ambulatorioveterinariopisillibertozzi.eu/userfiles/files/40306215438.pdfIn PDF document text
    • https://juvelyrikoscentras.lt/Files/file/47544671561.pdfIn PDF document text
    • http://caythuocnam.org/images/files/35238197492.pdfIn PDF document text
    • http://algarestofos.pnh.pt/js/ckfinder/userfiles/files/55650412042.pdfIn PDF document text
    • https://albertsdrukwerk.nl/bestanden/files/mobudu.pdfIn PDF document text
    • https://coachtourbusrental.com/wp-content/plugins/formcraft/file-upload/server/content/files/161f5ba22b1dcd---nenibifiwepugujeromawapum.pdfIn PDF document text
    • https://maritime-models.com/userfiles/file/futinevasomijiwenawezeso.pdfIn PDF document text
    • http://tincorner.vn/uploads/files/12206723589.pdfIn PDF document text
    • http://stressmanagement-karriere.de/userfiles/file/renolojoj.pdfIn PDF document text
    • https://kaemsp.org/upload/editor/file/deforuf.pdfIn PDF document text
    • http://bbfederico2.net/userfiles/file/mukavafel.pdfIn PDF document text
    • https://vida.posilatko.cz/files/wswg/file/nikedemesuxisapopubijob.pdfIn PDF document text
    • http://tks-forever.com/upload/2022/01/27/file/85562719363.pdfIn PDF document text
    • http://edilgroupdigiovanni.it/userfiles/files/4854743042.pdfIn PDF document text
    • http://mt-filtration.com/uploaded/file/97247955261649231b49d4.pdfIn PDF document text
    • http://www.scmphotography.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160f7a5d424ad6---koludemomarovadatu.pdfIn PDF document text
    • http://cableesmaltado.com/d/files/popajawusuzaj.pdfIn PDF document text
    • https://www.cukoyem.com.tr/wp-content/plugins/super-forms/uploads/php/files/g7sut2oq7lulf6rlud9smudm92/46032255204.pdfIn PDF document text
    • https://noriupapildu.lt/ckfinder/userfiles/files/34222824352.pdfIn PDF document text
    • http://www.deewanalarab.com/up_imgs/81522411768.pdfIn PDF document text
    • http://cukiernia-waltar.pl/qcms/userfiles/file/76805438556.pdfIn PDF document text
    • https://vandolderskb.com/images/usr/wipasaxubuwivodasezofagid.pdfIn PDF document text
    • http://www.mediacomriccione.it/wp-content/plugins/formcraft/file-upload/server/content/files/1616bcd0bc888d---9201269138.pdfIn PDF document text
    • https://fond.ru/userfiles/file/22274556343.pdfIn PDF document text
    • http://swiss-ex.com/images/blog/file/fovamewe.pdfIn PDF document text
    • http://xn----7sbabaajmdfbk3ddf3azka3b6a2r.xn--p1ai/ckfinder/userfiles/files/suvobotumotu.pdfIn PDF document text
    +10 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0004a618.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4A618 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_01_sfnt_off0004bd44.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4BD44 10620 bytes
SHA-256: c4a282fbc1b93aea52132b6b47b7e59557feac82f2e0438435c6b0ae59aebd18
font_02_sfnt_off0004d54e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4D54E 16936 bytes
SHA-256: 2531dd6315a8590c261dbe91fc13327468cb9c3330eac66752200e34131c64b0