Malicious PDF — malware analysis report

Static analysis result for SHA-256 2589884db0463e6f…

MALICIOUS

PDF

317.0 KB Created: 2022-02-25 02:06:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-07-12
MD5: d374fc2d2f06ee1372e57c698a0d402d SHA-1: 520ae58a932cdc8d103e568746821e97f51b0b69 SHA-256: 2589884db0463e6f1aa5c4627573170da84e452afc6bcc3e21d9d51bf5311eab
296 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.5871

Heuristics 8

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • QR business lure with obfuscated text critical PDF_QR_BUSINESS_LURE_OBFUSCATED_TEXT
    PDF contains a QR-like image and business-process scan instructions that only match after removing invisible Unicode control characters. This indicates deliberate text obfuscation in a QR phishing lure rather than a normal QR code.
  • Viral-video clickbait PDF links to suspicious host critical SE_VIRAL_VIDEO_CLICKBAIT_LINK
    Document uses viral/leaked-video lure text and links to a suspicious disposable-looking web host. This is a clickbait/traffic-scam carrier shape rather than a benign PDF link.
  • QR-code business verification phishing lure high PDF_QR_PHISHING_LURE
    PDF contains a QR-like image and visible text instructing the recipient to scan or use a QR code for verification, HR, payroll, policy, email, signature, or similar business-process activity. This is a high-signal quishing pattern even when the PDF has no active JavaScript or URI action.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kientrucnhacuagio.com/upload/files/53159866168.pdf In PDF document text
    • http://appartenvue.net/appart/upload/images/bozigomenedamobixamob.pdfIn PDF document text
    • https://cvsc.co/userfiles/file/28517430297.pdfIn PDF document text
    • https://www.blackandwhite-salon.com/wp-content/plugins/super-forms/uploads/php/files/514def397af84cb4a6c77291a0e5a35d/98808526688.pdfIn PDF document text
    • http://e-kva.ru/admin/ckfinder/userfiles/files/bafaxojutivinoko.pdfIn PDF document text
    • https://kungfuclasshongkong.com/louis/taichi/ckfinder/userfiles/files/jepesavuguwaxizupa.pdfIn PDF document text
    • https://hophamthaibinh.com/upload/files/77216033155.pdfIn PDF document text
    • https://wroclawmodelshow.pl/ckfinder/userfiles/files/59177746724.pdfIn PDF document text
    • http://safeabortionnepal.com/userfiles/file/lotumud.pdfIn PDF document text
    • https://alpinebadmintonacademy.com/ckfinder/userfiles/files/xuzejit.pdfIn PDF document text
    • http://sibzakon.ru/ckfinder/userfiles/files/31162282973.pdfIn PDF document text
    • https://www.antoniopopolizio.it/ckfinder/userfiles/files/lebaluniwumev.pdfIn PDF document text
    • http://julianina.dk/upload/file/gudejidirej.pdfIn PDF document text
    • https://www.cocochan.com.pk/wp-content/plugins/super-forms/uploads/php/files/d634b05b44c48eb68d725935f7d3afa4/vurovufeso.pdfIn PDF document text
    • https://www.abrasco.org.br/ckfinder/userfiles/files/54403848887.pdfIn PDF document text
    • https://mobspace.xyz/web/img/podborky/files/56261226368.pdfIn PDF document text
    • https://michalheger.cz/soubory/files/lexogulakosexatitawifog.pdfIn PDF document text
    • http://ave-france.com/pics/files/ditirinulimifi.pdfIn PDF document text
    • http://cobweb.janci.net/upload/files/kilelobaloderamoxuv.pdfIn PDF document text
    • http://yamamatoen-wanwan.jp/ckfinder/userfiles/files/32098571253.pdfIn PDF document text
    • https://bulkleynechako.gocascadia.com/images/cms/file/89940060930.pdfIn PDF document text
    • https://wietsevoermans.nl/ckfinder/userfiles/files/jeluzutanoba.pdfIn PDF document text
    • http://cuatro-pr.org/sites/default/files/file/27504585334.pdfIn PDF document text
    • http://traviet36.com/upload/files/65794989996.pdfIn PDF document text
    • http://tat.tatagrohimservis.ru/files/tiwobuxekadajemifajapet.pdfIn PDF document text
    • https://anglers.mtcserver6.com/UserFiles/File/55388956663.pdfIn PDF document text
    • http://worldnaturalfood.com/image/upload/File/talevenetilig.pdfIn PDF document text
    • http://kronospan-mofa-hungary.hu/editor_up/60831507532.pdfIn PDF document text
    • http://hftyby.com/upload_fck/file/2021-10-7/20211007141329842475.pdfIn PDF document text
    • http://dochoiotovn.com/uploads/userfiles/file/mobeguvixuxo.pdfIn PDF document text
    • http://landpas.pl/upload/file/nukuxarulek.pdfIn PDF document text
    • http://davisnewfoundlandfamilyreunion.com/clients/60627/File/30313424482.pdfIn PDF document text
    • http://104.156.58.56/~web2inbox/wp-content/plugins/formcraft/file-upload/server/content/files/161088b75c1ea1---10820293820.pdfIn PDF document text
    • http://market-oborudovanie.ru/upload/file/dalakaxupapubal.pdfIn PDF document text
    • http://firegallery.ru/img/upload/rovixokoxamotolilefijalaw.pdfIn PDF document text
    • http://aquitaine.annuaire-regional.com/ckfinder/userfiles/files/xuporopiso.pdfIn PDF document text
    • https://mifuj.co.za/XSRYdR1H?utm_term=fox+news+indianapolis+reportersPDF link annotation
    • https://www.sdhbd.org/backend/web/kcfinder/upload/files/ketazusimufe.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off000466c6.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off000466c6.bin)

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000466c6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x466C6 16132 bytes
SHA-256: 071bac7a3a90310621307d68123817e30fba7c89f9e5021c4391eb43bd8b9137
font_01_sfnt_off00047c3d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x47C3D 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_02_sfnt_off00049358.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x49358 21020 bytes
SHA-256: d7d47bbb585f638e2d95941cc825c54c4c4d90c46959f473c121723d73edd30a
font_03_sfnt_off0004cb0f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4CB0F 10552 bytes
SHA-256: 1189d03c02aa7b78799c50332ad0f680623d1603d8e0e7e1de32c61a41493e42