Malicious PDF — malware analysis report

Static analysis result for SHA-256 25c5f120da77a6c9…

MALICIOUS

PDF

355.8 KB Created: 2022-04-10 01:52:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-02
MD5: fbe8f4dcf1d3580ee4a6207cf95ed61c SHA-1: a4f9315ed259fc618b639c272cf58cb7cf5326aa SHA-256: 25c5f120da77a6c9af92a63ff48a58d826bb26658a36daedfa65e19197244e8c
169 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.6533

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF advertises pirated movie streaming/download medium PDF_PIRACY_STREAMING_LURE
    PDF rendered text advertises free full-movie streaming or download using piracy-brand names or a 'full movie + download/free/watch' intent phrase — recovered after folding the styled Unicode confusables the campaign uses to hide those keywords from plain-text detection. These are disposable SEO-spam carriers that route users to malvertising, fake-player, and scam pages; the PDF itself is inert.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaongonmaiphuong.vn/webroot/img/files/tekufu.pdf In PDF document text
    • https://rogifegupoxixo.weebly.com/uploads/1/3/4/0/134040774/tuxopa-tukunagatifobi-bitizajawumo-pizagezizi.pdfIn PDF document text
    • http://lor-rostov.su/userfiles/files/nivefexawun.pdfIn PDF document text
    • https://jekudadej.weebly.com/uploads/1/3/5/3/135301654/45e8cf23dc00bab.pdfIn PDF document text
    • https://gbp.dropship-online.com/userfiles/files/75070660859.pdfIn PDF document text
    • https://peusch.lu/userfiles/files/30657691747.pdfIn PDF document text
    • http://hanker.ru/web/img/files/21284312389.pdfIn PDF document text
    • https://bugajujifupub.weebly.com/uploads/1/3/4/8/134894919/wibegogu_pugilakinejo_mapowifop_gopinaradiliw.pdfIn PDF document text
    • http://nc2e.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1621e5b4fa4725---81010409581.pdfIn PDF document text
    • http://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/1621d6e47f13ce---81569742552.pdfIn PDF document text
    • https://zinimejab.weebly.com/uploads/1/3/4/6/134653802/c603ed4bb.pdfIn PDF document text
    • https://gerudupox.weebly.com/uploads/1/3/2/7/132712596/lazozitufogev-pejimot-rafopuwozefire-tanalefufiw.pdfIn PDF document text
    • https://luwujapi.weebly.com/uploads/1/3/4/7/134751522/loxalige.pdfIn PDF document text
    • http://gulfapex.com/uploads/file/tarajenupa.pdfIn PDF document text
    • https://tajerupabud.weebly.com/uploads/1/3/1/1/131164315/mevelaje.pdfIn PDF document text
    • http://tuv-zimer.co.il/assets/userfiles/files/wekapax.pdfIn PDF document text
    • https://hiroyoung.com/data/files/zomiropemilarobo.pdfIn PDF document text
    • https://pupagabizazupi.weebly.com/uploads/1/3/5/3/135314982/romipufugik.pdfIn PDF document text
    • http://gyn-ordi.at/myPix/file/46180675295.pdfIn PDF document text
    • https://wotowabe.weebly.com/uploads/1/3/4/6/134688823/luzevu-bedugejakepefem-banin-xexetefuvabi.pdfIn PDF document text
    • https://zidadosivifaju.weebly.com/uploads/1/3/0/7/130775619/sowoteja_nipibujes_zudonulomes_mulupoxoregogi.pdfIn PDF document text
    • https://gidakilubokaz.weebly.com/uploads/1/3/4/6/134607675/jubemiwugabipa-nobufafa.pdfIn PDF document text
    • https://ramilelajebow.weebly.com/uploads/1/3/4/6/134647205/92ed3386d5e7e4.pdfIn PDF document text
    • http://divapharma.com/uploaded/file/31841374871.pdfIn PDF document text
    • https://nufomesamibu.weebly.com/uploads/1/3/5/3/135332564/90939.pdfIn PDF document text
    • https://ruvawuwejijexut.weebly.com/uploads/1/3/0/8/130814193/39a04.pdfIn PDF document text
    • https://zajolapa.weebly.com/uploads/1/3/0/7/130776493/308998.pdfIn PDF document text
    • http://indcms.testingmachines.com/images/file/18552924073.pdfIn PDF document text
    • https://gulecbakliyat.com/panel/kcfinder/files/62877586739.pdfIn PDF document text
    • https://plentis.eu/ckfinder/userfiles/files/nutikore.pdfIn PDF document text
    • http://saludocupacionalpso.com/home/wp-content/plugins/formcraft/file-upload/server/content/files/1620cbf4ec4818---kupoveke.pdfIn PDF document text
    • https://mapadubedebo.weebly.com/uploads/1/3/6/0/136095435/zugufedovo.pdfIn PDF document text
    • http://mybooksite.net/kcfinder/files/30898299031.pdfIn PDF document text
    • https://xifufakeva.weebly.com/uploads/1/3/0/7/130775652/zuguwelif.pdfIn PDF document text
    • https://nopefulewipedu.weebly.com/uploads/1/3/4/3/134314682/7166863.pdfIn PDF document text
    • https://legalages.weebly.com/uploads/1/3/4/4/134442537/rasarolij.pdfIn PDF document text
    • https://wifevotus.weebly.com/uploads/1/3/4/8/134897576/kopewasu.pdfIn PDF document text
    • http://rootbeadmill.com/upload_fck/file/2022-3-20/20220320000302718263.pdfIn PDF document text
    • http://artechq8.com/beta/uploads/files/lezebufukipos.pdfIn PDF document text
    • https://nitetawowi.weebly.com/uploads/1/3/5/3/135301411/babamatasojat.pdfIn PDF document text
    • http://www.ztc.hekko24.pl/panel/kcfinder/upload/files/51062287140.pdfIn PDF document text
    • http://boq.internet-match.com/upload/files/kejez.pdfIn PDF document text
    • https://pokumajapemen.weebly.com/uploads/1/3/4/4/134490217/migapakopiw.pdfIn PDF document text
    • http://paradisetourkorea.com/FileData/ckfinder/files/20220319_2BC06D3540B1BB5F.pdfIn PDF document text
    • https://jovawesuranabi.weebly.com/uploads/1/3/1/3/131379439/1446340.pdfIn PDF document text
    • https://samsungklimamodelleri.com/upload/ckfinder/files/mibedivuwedik.pdfIn PDF document text
    • https://sunuf.co.za/XSRYdR1H?utm_term=now+you+see+me+gomoviesPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    +5 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000523b5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x523B5 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off00053bcc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x53BCC 10284 bytes
SHA-256: 0f1ff0c603e5fab0938862512b35621087152809b46f41aca6099dbd93bc2dfb
font_02_sfnt_off0005530e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5530E 17296 bytes
SHA-256: fa8be1e58aa6d76b5f4dfcc0d0eb59fc1b471d0b91fc3fb5f97b3f674e850a2b