Malicious PDF — malware analysis report

Static analysis result for SHA-256 4413c50423a8e819…

MALICIOUS

PDF

233.0 KB Created: 2022-03-18 08:50:36 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-05
MD5: 687f8f4b79b83b8bc70b94c7a1267d83 SHA-1: cedd5a4f26902464dcf4a73f5a0c809a35990438 SHA-256: 4413c50423a8e8198cf3d8b39fd1633bdd1b76d44e3a7e409aba8babd499cad8
136 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9577

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://jysfh.com/upload_fck/file/2022-2-9/20220209200542697253.pdf In PDF document text
    • https://businesslife.com/content/files/83876488286.pdfIn PDF document text
    • https://pensiunea-escape.ro/ckfinder/userfiles/files/fefemomaxil.pdfIn PDF document text
    • http://medcentervrn.ru/userfiles/files/posevajefekoduredup.pdfIn PDF document text
    • http://www.amis-simserhof.fr/kcfinder/upload/files/matelogiwilisijojibajuf.pdfIn PDF document text
    • https://itracmediav5.com/ckfinder/userfiles/files/supuv.pdfIn PDF document text
    • http://www.tivafa.hu/upload/file/jezerovuzi.pdfIn PDF document text
    • http://www.ppspr.org.br/ckeditor/kcfinder/upload/files/94351974363.pdfIn PDF document text
    • http://www.amis-simserhof.fr/kcfinder/upload/files/vodogixunugifidod.pdfIn PDF document text
    • https://www.afsti.org/admin/kcfinder/upload/files/81194951881.pdfIn PDF document text
    • https://oreopay57.com/ckfinder/userfiles/files/sinozekikodumexagavi.pdfIn PDF document text
    • http://tua-hatextiles.com/assets/ckeditor/kcfinder/upload/files/1493242630.pdfIn PDF document text
    • https://sensilove.vn/upload/fck/file/24534252508.pdfIn PDF document text
    • http://fcgo.tw/uploadpic/files/tufujebosipotekobuxik.pdfIn PDF document text
    • http://hmarksltd.com/assets/ckeditor/kcfinder/upload/files/60981617585.pdfIn PDF document text
    • https://hankilfood.com/upfile/files/57882892146.pdfIn PDF document text
    • https://ecotranslation.ca/upload/editor/file/54106223316.pdfIn PDF document text
    • http://exdebt.bg/userfiles/file/77796506014.pdfIn PDF document text
    • https://doradca-bankowy.pl/files/files/45618866472.pdfIn PDF document text
    • https://merten-rozetki.su/kcfinder/upload/files/1834499330.pdfIn PDF document text
    • http://medianet2000.net/amm_prod/image_news_popup/file/jejuramopup.pdfIn PDF document text
    • https://cian.hr/userfiles/file/jikelodalopom.pdfIn PDF document text
    • https://roundtable106trust.org/admin/uploads/file/49151867278.pdfIn PDF document text
    • https://perfectsextherapy.com/public_html/userfiles/file/fojizajitujagasi.pdfIn PDF document text
    • http://ucg-eg.com/userfiles/file/mevejez.pdfIn PDF document text
    • http://krajcsovicz.hu/kcfinder/upload/files/45988573909.pdfIn PDF document text
    • https://daaeportrett.no/upload/file/xogalalubanuvit.pdfIn PDF document text
    • http://test.xn--b1adbeobutb0arf.xn--p1ai/kcfinder/upload/files/84762777138.pdfIn PDF document text
    • https://tevav.co.za/XSRYdR1H?utm_term=quakers+hill+nursing+home+coroner%27+s+reportPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0003328e.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0003328e.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0003328e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3328E 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_01_sfnt_off000349ae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x349AE 11108 bytes
SHA-256: 140c8fa144cb1e961483654072c80e900a9dd9ccaf788048aba6b5c000679f65
font_02_sfnt_off0003638a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3638A 19044 bytes
SHA-256: e619566ce8219005bbcc8632b55db0abe6c9f98feff2ce71b894b61eeb31f307