Malicious PDF — malware analysis report

Static analysis result for SHA-256 22bb8d51b6f19947…

MALICIOUS

PDF

76.4 KB Created: 2020-11-23 11:45:08 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-03
MD5: eb31095da9a09c863bd9b25265ac89b3 SHA-1: 465e81e4d21f8ac5131b2c08e20ceea4a759365d SHA-256: 22bb8d51b6f1994726d4467839aaa57d6486e8137a7a8e268a4c8ee715853311
254 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/strik?utm_term=cheerleader+sheet+music+trumpet In PDF document text
    • https://cdn-cms.f-static.net/uploads/4408873/normal_5f95bb96589da.pdfIn PDF document text
    • https://wudizibi.weebly.com/uploads/1/3/4/4/134477582/lisusivari.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370074/normal_5f91fae61df7a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4386836/normal_5f90d16be73b7.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4368972/normal_5f9d005b72ef5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4486765/normal_5faed874517bb.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374372/normal_5f8deea1a0f95.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4408707/normal_5fb5c0091b2f6.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/b2be9645-4fbc-47a7-aa18-e1be13b059b5/41934656120.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8a809c3b-751f-40b5-9078-f7488d30bd06/newososudoxata.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/83416166-b8f8-4f55-8da0-fb14536a2602/didoluretatumururer.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bbfdc04e-004b-4cee-8b72-edabc6dd45c1/ford_mustang_gt-_500.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6906ce84-f649-4bc7-ac88-2bf9fbbeae4c/pioneer_elementary_school_asd20.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/80be75ec-30a0-4c57-a6da-852c550bee66/75453007543.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d8ad.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD8AD 5220 bytes
SHA-256: 840f5b16282a0ebdbe1a7fc9d79e856fe13de6abc5fa726e010dacdff68d255d
font_01_sfnt_off0000ea39.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEA39 11008 bytes
SHA-256: ce32904de780a4219d1d408a62b6dd2a6e2f988c7715bcf576ba1fe5c43c27b1
font_02_sfnt_off00010fb9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10FB9 16100 bytes
SHA-256: b59afbb2f683942213df284fd86cd9422ada0c5f1ffac7698db8c94a40390bc4