Malicious PDF — malware analysis report

Static analysis result for SHA-256 2f86940eb71ad95a…

MALICIOUS

PDF

525.2 KB Created: 2022-03-03 09:20:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-25
MD5: b0b0ebb4a9cba571d4c94eb0d8f317ac SHA-1: c06394b6c438f46f9c8795818138a696fc00acb1 SHA-256: 2f86940eb71ad95a611ab450c2bf0df74501ccb3282347e2f036fb4794f3b081
136 Risk Score

Machine Learning

  • Nyx PDF Classifier suspicious score 0.3620

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lovig.co.za/XSRYdR1H?utm_term=poker+5+card+guide PDF link annotation
    • http://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/162149c0cdbb78---10797215595.pdfIn PDF document text
    • http://spgcplb.com/ckeditor/kcfinder/upload/files/25904961376.pdfIn PDF document text
    • https://monyetmesum.com/contents/files/kofilug.pdfIn PDF document text
    • https://wamsconference.com/wp-content/plugins/super-forms/uploads/php/files/b3ba1ec029bf56ebfed88370b4ab6f39/bazelazulexolozikijon.pdfIn PDF document text
    • http://tianfonmm.com/d/files/tugenebonukorud.pdfIn PDF document text
    • http://arbigaz.com.tr/panel/kcfinder/upload/files/tuzaninalejulabisa.pdfIn PDF document text
    • https://rayvoltbike.tw/geektic/files/rafajufidegag.pdfIn PDF document text
    • https://dassti.cl/admin/uploads/file/nisogujiwen.pdfIn PDF document text
    • http://leaguengn.com/userfiles/file///buvamigatugaxelegapom.pdfIn PDF document text
    • http://vitanova-cattery.com/upload/file/tetotorefatapabone.pdfIn PDF document text
    • http://asirius.su/wp-content/plugins/super-forms/uploads/php/files/7e5784a26780dfbcb1788eb8fafeabae/zopep.pdfIn PDF document text
    • https://cet.sk/res/file/xesen.pdfIn PDF document text
    • http://minerva-collection.net/files/files/65725429685.pdfIn PDF document text
    • http://cmtsport.com/pliki/sekasezom.pdfIn PDF document text
    • http://rent-lease-no1.com/userfiles/file/20220218162957.pdfIn PDF document text
    • http://nahar-bd.com/assets/ckeditor/kcfinder/upload/files/91243827518.pdfIn PDF document text
    • http://www.rebranded.tv/wp-content/plugins/formcraft/file-upload/server/content/files/161fba1dd107fd---82314563458.pdfIn PDF document text
    • http://www.sparkprototypes.com/wp-content/plugins/formcraft/file-upload/server/content/files/16217242009643---suxinebil.pdfIn PDF document text
    • https://bodymason.com/user_uploads/files/nuwego.pdfIn PDF document text
    • https://www.dyna-tech.nl/wp-content/plugins/formcraft/file-upload/server/content/files/161f9eb03626bb---wurara.pdfIn PDF document text
    • http://prosquash.by/data/90540159231.pdfIn PDF document text
    • https://ooo-kenk.ru/userfiles/file/vitopozunagirepizix.pdfIn PDF document text
    • https://nsck-cykelmotion.dk/userfiles/file/39236982156.pdfIn PDF document text
    • https://diphong.com/uploads/29913589190.pdfIn PDF document text
    • http://resortvillairene.it/userfiles/files/givabumedibuxilisapuvixu.pdfIn PDF document text
    • http://bmcnx.com/userfiles/file/juribimututezuduj.pdfIn PDF document text
    • http://everestsherpatravel.com/demo/public/ckeditor/kcfinder/upload/files/jinetovamubeluxoro.pdfIn PDF document text
    • https://deniz-sogutma.org/img/userfiles/file/11019933276.pdfIn PDF document text
    • http://orsini-blasioli.it/userfiles/files/tusavilem.pdfIn PDF document text
    • https://sarikasocatering.com/assets/publik/files/24142545535.pdfIn PDF document text
    • http://wetravels.com/kcfinder/upload/files/31442614727.pdfIn PDF document text
    • http://urs-certification.com/gais/image/file/86009834142.pdfIn PDF document text
    • http://www.louervendreaumaroc.com/kcfinder/upload/files/tubexokajed.pdfIn PDF document text
    • https://semineebrasov.ro/printuri-fi/files/24295569341.pdfIn PDF document text
    • http://meghdoothsuzuki.com/uploads/gokepi.pdfIn PDF document text
    • https://htchninc.com/d/files/2465184361.pdfIn PDF document text
    • https://aquamedicasatumare.ro/ckfinder/userfiles/files/26662095308.pdfIn PDF document text
    • https://sakata-mokuzai.com/db/item/uploads/files/26696053864.pdfIn PDF document text
    • http://humanprojekt.lenti.hu/feltoltes/files/52800756749.pdfIn PDF document text
    • http://smartvoicesys.com/userfiles/ledevotitov.pdfIn PDF document text
    • http://piwcnorthhouston.org/admin/ckeditor/kcfinder/upload/files/92458646629.pdfIn PDF document text
    • http://hengelo.scholenkeuze.nl/UserFiles/files/gajov.pdfIn PDF document text
    • http://business-baltic.com/myfiles/dok/sebetavewazofixif.pdfIn PDF document text
    • https://smlstripedbass.com/home/rock/public_html/ckfinder/userfiles/files/napaleguk.pdfIn PDF document text
    • http://driver-jazda.pl/upload/file/49600508087.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    +4 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0007c40d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7C40D 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_01_sfnt_off0007db2d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7DB2D 10456 bytes
SHA-256: 061f71054ac570fd2e9939f1db80f7fb867ded3d4a1a4ac8063c34eb12f7ff46
font_02_sfnt_off0007f2dc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7F2DC 18296 bytes
SHA-256: d29dbbb4a5b506683488e134e502ad1d15a3a7ae3b7a0b72d95900cefdb5bc03