Malicious PDF — malware analysis report

Static analysis result for SHA-256 4412dc0ce60f4ff5…

MALICIOUS

PDF

362.5 KB Created: 2022-04-09 11:52:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-05
MD5: c04b38a325d8fd34ab39f295ce7d339a SHA-1: 2b4c2b322191cc8b2fe6b086feac3b291dee177e SHA-256: 4412dc0ce60f4ff59b5d8801d7ae7f6d9b7bd2034fadf244908ad7998beb0426
136 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.6763

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://parejalecaros.com/adjunto/upload/fck/files/rafemufezomanavebod.pdf In PDF document text
    • https://mumixiginuwogi.weebly.com/uploads/1/3/4/7/134752923/ximilo-muzuxenodo-konese-natori.pdfIn PDF document text
    • https://zideloxilatomi.weebly.com/uploads/1/3/5/3/135325243/f6361.pdfIn PDF document text
    • http://www.shipsupply.co.mz/wp-content/plugins/formcraft/file-upload/server/content/files/162055338ef2fc---42427384711.pdfIn PDF document text
    • https://kekulepolunan.weebly.com/uploads/1/3/4/8/134889268/fafofopupevusi.pdfIn PDF document text
    • https://xereritotof.weebly.com/uploads/1/3/1/0/131070340/5355416.pdfIn PDF document text
    • http://mail.teleserviciomalaga.com/ckfinder/userfiles/files/12934812841.pdfIn PDF document text
    • https://sepiboberad.weebly.com/uploads/1/3/1/1/131164555/2657533.pdfIn PDF document text
    • https://biwusime.weebly.com/uploads/1/4/1/2/141219861/zekuzozagom.pdfIn PDF document text
    • https://houseofwax.eu/kcfinder/upload/files/mefasa.pdfIn PDF document text
    • https://wuxotiwor.weebly.com/uploads/1/3/4/3/134335057/gofewevel.pdfIn PDF document text
    • https://nuvipepive.weebly.com/uploads/1/3/1/4/131409498/4967266.pdfIn PDF document text
    • https://tumotasefon.weebly.com/uploads/1/3/5/3/135317172/1348712.pdfIn PDF document text
    • https://gifutemosi.weebly.com/uploads/1/4/1/3/141317822/sinowivubutirejoruxa.pdfIn PDF document text
    • https://fileduwefevara.weebly.com/uploads/1/3/4/3/134384607/josivo.pdfIn PDF document text
    • http://radiosalsa.fr/php/rs/filesupload/file/93161878877.pdfIn PDF document text
    • https://ruwefenoref.weebly.com/uploads/1/3/0/7/130739117/1390652.pdfIn PDF document text
    • https://fusorebumobem.weebly.com/uploads/1/3/3/9/133986296/4138886.pdfIn PDF document text
    • http://cabini.it/userfiles/files/loxukamatazatepusixa.pdfIn PDF document text
    • https://nuruvubapifak.weebly.com/uploads/1/3/1/4/131452890/leromebik.pdfIn PDF document text
    • https://zuxadozi.weebly.com/uploads/1/3/4/6/134662888/b5eef4c8d3c73.pdfIn PDF document text
    • https://tubozabuzimez.weebly.com/uploads/1/3/4/8/134878922/b485ea568fb5996.pdfIn PDF document text
    • https://losuwigawoje.weebly.com/uploads/1/3/5/3/135304717/703828.pdfIn PDF document text
    • https://mejoraxu.weebly.com/uploads/1/3/1/3/131380998/rokidemow.pdfIn PDF document text
    • https://www.mercato.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/161fdad504112e---9328881045.pdfIn PDF document text
    • https://luxufaxunixepu.weebly.com/uploads/1/3/4/5/134584211/kizomometabukix.pdfIn PDF document text
    • https://tenanetudoji.weebly.com/uploads/1/3/4/2/134266315/9028598.pdfIn PDF document text
    • https://yoyep.co.za/XSRYdR1H?utm_term=form+st+810PDF link annotation
    • http://kup-vino.cz/web/ckfinder/userfiles/files/sukun.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off00053747.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off00053747.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00053747.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x53747 11784 bytes
SHA-256: dd1bc5fe0a44f75c4eeaee475a4d7d33d9df2ad46231b25310012dd24343484c
font_01_sfnt_off000553c2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x553C2 18120 bytes
SHA-256: 06558fcb50ecf9c6b8d8cc31fc62c4c6f9f10605bb7f72459e69e5dc4a59026d
font_02_sfnt_off000582e6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x582E6 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1