Malicious PDF — malware analysis report

Static analysis result for SHA-256 18a5e6754c96a4bf…

MALICIOUS

PDF

274.2 KB Created: 2022-04-26 02:00:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-10
MD5: 5aa72a87c8b9d0c5e51cf282b9c71d8c SHA-1: bf353157678dace736a9df02f88789ff1940eee9 SHA-256: 18a5e6754c96a4bf31b8ba64062a5ba61c38e3e63977d3a7a197d323194e0b78
166 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.5476

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yubit.co.za/XSRYdR1H?utm_term=metal+gear+survive+xbox+one PDF link annotation
    • https://www.sidertest.it/wp-content/plugins/formcraft/file-upload/server/content/files/1625692017e62b---85733427055.pdfIn PDF document text
    • https://forssah.co/userfiles/file/somunejevipudugi.pdfIn PDF document text
    • https://bazugibeb.weebly.com/uploads/1/3/1/4/131453150/dewemelikazin.pdfIn PDF document text
    • http://csc0851.com/userfiles/file/20220407085604_j942vz.pdfIn PDF document text
    • https://gofizunesiwez.weebly.com/uploads/1/3/0/8/130874053/548278.pdfIn PDF document text
    • http://ranch.pl/files/file/fejigejolowomite.pdfIn PDF document text
    • https://californiaoptionsrealestate.com/wp-content/plugins/super-forms/uploads/php/files/c31d3898326425417cdc4f5c4e7995f4/pumugitosijotirogulal.pdfIn PDF document text
    • https://xunipemadigorof.weebly.com/uploads/1/3/0/8/130813553/1de029dca9.pdfIn PDF document text
    • http://maxitelt.no/wp-content/plugins/formcraft/file-upload/server/content/files/1626585e617320---6357754445.pdfIn PDF document text
    • http://www.letnifestiwal.pl/ckfinder/userfiles/files/fapadizizazagigumagit.pdfIn PDF document text
    • https://moveo-sport.pl/userfiles/file/muparoxen.pdfIn PDF document text
    • https://jukewamozaf.weebly.com/uploads/1/3/1/4/131438013/7429734.pdfIn PDF document text
    • http://global-gypsum.com/wp-content/plugins/formcraft/file-upload/server/content/files/1625504f3f1b34---52073930174.pdfIn PDF document text
    • http://ymjgolf.com/file_media/file_image/file/sofidobufawalulosevunole.pdfIn PDF document text
    • https://pareruli.weebly.com/uploads/1/3/4/8/134891857/3812233.pdfIn PDF document text
    • http://geometracosentino.com/userfiles/files/lixaxopuwik.pdfIn PDF document text
    • https://temahr.hr/files/97008154191.pdfIn PDF document text
    • http://studiotecnicodambra.eu/userfiles/files/vevavil.pdfIn PDF document text
    • http://qianxish.com/ckfind_image/files/kokevek.pdfIn PDF document text
    • http://ambvetesopo.eu/userfiles/files/vegopumovetovogesu.pdfIn PDF document text
    • https://www.bsff.com/kcfinder/upload/files/xapakemepivemolesadametu.pdfIn PDF document text
    • http://smelawservice.com/file_media/file_image/file/zibox.pdfIn PDF document text
    • http://onlinemidias.com/ckfinder/userfiles/files/45903248479.pdfIn PDF document text
    • http://bfup.org/ckeditor/kcfinder/upload/files/38081060664.pdfIn PDF document text
    • https://poxemitiwafu.weebly.com/uploads/1/3/1/8/131871555/texipezituxime.pdfIn PDF document text
    • https://kewikadovus.weebly.com/uploads/1/3/4/7/134746666/474bf437bd0c48.pdfIn PDF document text
    • https://www.giromarilia.com.br/plugins/kcfinder/upload/files/tirurinogevozogibarame.pdfIn PDF document text
    • https://losebevaxefot.weebly.com/uploads/1/3/5/3/135347065/5b5f7b0a.pdfIn PDF document text
    • http://meyergarden.com/ckfinder/userfiles/files/bizine.pdfIn PDF document text
    • https://zirubelazuzo.weebly.com/uploads/1/3/4/7/134747961/b553eb935.pdfIn PDF document text
    • https://netajeripen.weebly.com/uploads/1/3/6/0/136053717/fiwibufewewabodez.pdfIn PDF document text
    • http://seosanhrd.com/userfiles/file/74340827045.pdfIn PDF document text
    • https://pijusutuwo.weebly.com/uploads/1/3/1/4/131407307/1e2133f4.pdfIn PDF document text
    • https://gutomaxitokivi.weebly.com/uploads/1/3/1/3/131383747/luverezejapakidaj.pdfIn PDF document text
    • https://lumurali.weebly.com/uploads/1/3/4/6/134640239/dofetu.pdfIn PDF document text
    • http://povprojekt.cz/upload/files/88422101554.pdfIn PDF document text
    • http://anantasandesh.com/dbros/public/ckeditor/kcfinder/upload/files/befabejidavidumewodideri.pdfIn PDF document text
    • http://www.barczyk.plwww.sgpm.krakow.pl/aanewsysn/kcfinder/upload/files/titizova.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0003c826.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0003c826.bin)

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0003c826.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3C826 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off0003e038.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3E038 19228 bytes
SHA-256: 9973c16f0e4d962316d0b873903d5f98679e19e5048c100a28a5461e9240ebe0
font_02_sfnt_off000410e2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x410E2 3784 bytes
SHA-256: f81559dcae1507d9294b1644a92a15a2ab90ea52e0364b8f8b438a60b50ef7cb
font_03_sfnt_off00041fbe.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x41FBE 10684 bytes
SHA-256: 9569c6bfdd0fbfaece742ac965ad3bd48579ed3a908783945f209152b91b041c