Malicious PDF — malware analysis report

Static analysis result for SHA-256 22b97b20f5d51dfc…

MALICIOUS

PDF

204.9 KB Created: 2022-02-21 06:16:20 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-06-02
MD5: 44cfb83c92c34f834bdde9ab1d41f53b SHA-1: 16cf89f041672523855983c50cc8bb69af9094bd SHA-256: 22b97b20f5d51dfcfb28fa75a185f496b85bee6c83704d30e4b127f9b63045be
166 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.7551

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://norin.co.za/XSRYdR1H?utm_term=gloomhaven+class+guide+mindthief PDF link annotation
    • https://atcotourismtravel.com/userfiles/file/50693256760.pdfIn PDF document text
    • https://laxmigrouppune.com/wp-content/plugins/super-forms/uploads/php/files/ca7a83c2136e9afe4665b1b3d50fb44c/53309286929.pdfIn PDF document text
    • http://crislbd.com/public/admin/assets/ckeditor/kcfinder/upload/files/30363185319.pdfIn PDF document text
    • http://novussiteyonetimi.com/uploads/file/maligegosopekunigalovada.pdfIn PDF document text
    • http://diamantina-joaillerie.com/ckfinder/userfiles/files/89396494993.pdfIn PDF document text
    • https://nepaltrekkinginhimalaya.com/assets/userfiles/files/gibuwilon.pdfIn PDF document text
    • https://ask-it.softki.com/Ask-it/UserFiles/file///70344693930.pdfIn PDF document text
    • https://dgcollege.ac.in/assets/kcfinder/upload/files/rapexativipi.pdfIn PDF document text
    • https://sandalyecenneti.com/wp-content/plugins/super-forms/uploads/php/files/unqnnq9k6897kupnjbkiniem39/83328628752.pdfIn PDF document text
    • http://xavitec.com/cliente/conteudos/files/nexawetubamizu.pdfIn PDF document text
    • http://urbancollab.com/userfiles/Proj_Name//files/95856890068.pdfIn PDF document text
    • http://sunrui-ti.com/d/files/vabufojetexisudipano.pdfIn PDF document text
    • https://cope.lk/assets/media/file/nogewi.pdfIn PDF document text
    • https://esz.jp/img/editor/files/25427323935.pdfIn PDF document text
    • http://desushibar.com/userfiles/file/safip.pdfIn PDF document text
    • https://arizonapoolcontractor.com/wp-content/plugins/formcraft/file-upload/server/content/files/161ec2abb96f89---2542985305.pdfIn PDF document text
    • http://24hnbc.com/assets/ckfinder/core/connector/php/uploads/files/rudemofiwumiware.pdfIn PDF document text
    • http://stopguepes72.fr/userfiles/file/73837185055.pdfIn PDF document text
    • http://dailycan.com/userfiles/files/kifobodugoxamegedazupo.pdfIn PDF document text
    • https://www.newhorizonscrisiscenter.org/ckfinder/userfiles/files/tevosovarodi.pdfIn PDF document text
    • http://www.greenfield-sustainability.com/images/files/16761058429.pdfIn PDF document text
    • http://1careglobal.com/upload/files/kilezudimegobezosalafilek.pdfIn PDF document text
    • http://stmarysharipad.com/userfiles/file/77734222082.pdfIn PDF document text
    • https://implantsdentairesdesmoulins.com/upload/editor/file/82548242999.pdfIn PDF document text
    • http://josepholszowka.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/pafovujonobafonaligelale.pdfIn PDF document text
    • http://hsound.ro/images/custom/file/minexekuneximu.pdfIn PDF document text
    • http://sdtech-kh.com/kcfinder/upload/files/jurovipiwu.pdfIn PDF document text
    • http://auxerretv.com/content/public/file/55929347090.pdfIn PDF document text
    • https://newtop-eg.com/userfiles/file/23923285735.pdfIn PDF document text
    • http://bestforfishing.com/wp-content/plugins/super-forms/uploads/php/files/6988b60b736074ad9743a85eb4fd4348/42776509700.pdfIn PDF document text
    • https://amkboiler.com/wp-content/plugins/super-forms/uploads/php/files/gvq3qgnpe0lfbkvqcnrn6u4le1/4947116981.pdfIn PDF document text
    • http://vitajeans.com/ckfinder/userfiles/files/nekagizejewijimodaxadase.pdfIn PDF document text
    • https://antiquites-opio.com/kcfinder/upload/files/lusuvuriwotoronupaxexuvo.pdfIn PDF document text
    • http://wideanglepackaging.com/ckfinder/userfiles/files/nozoranak.pdfIn PDF document text
    • https://bamfieldrental.com/userfiles/file/33122795070.pdfIn PDF document text
    • http://ryukatsu.com/userData/board/file/muzeforexuw.pdfIn PDF document text
    • https://pannonfinanz.eu/editor_up/bolopupizo.pdfIn PDF document text
    • http://www.eventoptik.de/upload/files/retumepopuropunipo.pdfIn PDF document text
    • http://dnepropress.net/files/file/bupuxasuxoxo.pdfIn PDF document text
    • http://jerseybankruptcylaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/74809540650.pdfIn PDF document text
    • http://geology.ie/wp-content/plugins/formcraft/file-upload/server/content/files/1614618d90c485---9844948596.pdfIn PDF document text
    • http://barcelonahotel.vn/UpLoadFile/file/26594346327.pdfIn PDF document text
    • http://www.ztc.hekko24.pl/panel/kcfinder/upload/files/lewosozufutojosulazoren.pdfIn PDF document text
    • https://luyenthitoeic.info/userfiles/file/12697589607.pdfIn PDF document text
    • https://alarrabnews.com/images/content/content/file/wevedelafurowajetolukutem.pdfIn PDF document text
    • http://www.ausafrica.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/161e2dec6545bf---pesiwoxobopew.pdfIn PDF document text
    • http://kioskcondoweb.wpengine.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e8d4f6a1b95---70997310929.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    +6 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002c4a5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2C4A5 17840 bytes
SHA-256: 56310ffae82e24082082f5f070f67b7a2fd9d4ef3aa5f1cc0618df5f36a34c11
font_01_sfnt_off0002f313.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2F313 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_02_sfnt_off00030a35.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x30A35 11028 bytes
SHA-256: b65df6fa645d34d49a4a9788d319336368ea0c43aa383f966833072b70eb5fd4