Malicious PDF — malware analysis report

Static analysis result for SHA-256 4416e293b70b5859…

MALICIOUS

PDF

242.9 KB Created: 2022-04-09 16:04:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-05
MD5: de0236b93afc1d3234e90ed1f8abd404 SHA-1: 72d963a004a49012905f17d010e310e6152fae5e SHA-256: 4416e293b70b58591c302dd0d449806bbe8bcc5411dd925e5eb7a387e21a09e1
136 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.7802

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://sunuf.co.za/XSRYdR1H?utm_term=ping+i20+driver+reviews PDF link annotation
    • https://jipovosu.weebly.com/uploads/1/3/4/7/134728388/borat.pdfIn PDF document text
    • http://thegrcinstitute.org/app/webroot/js/ckfinder/userfiles/files/duxeg.pdfIn PDF document text
    • https://kexexetipo.weebly.com/uploads/1/3/4/8/134897314/3298ba31.pdfIn PDF document text
    • https://www.inkfactory.pk/wp-content/plugins/formcraft/file-upload/server/content/files/1620929e81a5a4---xuwamodutuwerakareximolax.pdfIn PDF document text
    • https://www.foodprocessingprojects.com/admin_assets/ckeditor/kcfinder/upload/files/rabexuzukux.pdfIn PDF document text
    • https://orangevelodrometrail.fr/img/uploads/files/39793744972.pdfIn PDF document text
    • https://wukuvapover.weebly.com/uploads/1/3/4/8/134878379/5628361.pdfIn PDF document text
    • http://dokturmice.com/ckfinder/userfiles/files/bibezurevatukopof.pdfIn PDF document text
    • https://riverasphotovideo.com/wp-content/plugins/formcraft/file-upload/server/content/files/162346a2de3981---47730907593.pdfIn PDF document text
    • https://nitiduzumamojas.weebly.com/uploads/1/3/7/5/137506598/6ffa226.pdfIn PDF document text
    • https://sazizilas.weebly.com/uploads/1/3/0/8/130874530/1477115.pdfIn PDF document text
    • https://bodivikofe.weebly.com/uploads/1/3/5/3/135332590/jesijetufumijugun.pdfIn PDF document text
    • https://fuvewoziju.weebly.com/uploads/1/3/4/8/134883365/2394337.pdfIn PDF document text
    • http://amsuatrust.org/survey/userfiles/files/nazowewitufofakerokela.pdfIn PDF document text
    • https://jewigilimeb.weebly.com/uploads/1/3/1/4/131408849/5242975.pdfIn PDF document text
    • https://wopuvonu.weebly.com/uploads/1/3/1/3/131384791/najimu_gapodaxoxinigit_zopibogaj.pdfIn PDF document text
    • https://wonenizawelob.weebly.com/uploads/1/3/4/3/134315845/531980.pdfIn PDF document text
    • https://dodoluwateja.weebly.com/uploads/1/3/1/3/131381806/balevigulinexorub.pdfIn PDF document text
    • http://caogenzhiben.com/filespath/files/20220406035504.pdfIn PDF document text
    • https://duguzimelape.weebly.com/uploads/1/3/4/6/134666192/fozekuv.pdfIn PDF document text
    • https://wuvukimepegoj.weebly.com/uploads/1/3/4/6/134694914/8f60edbb86f7.pdfIn PDF document text
    • http://noithattamphuong.com/upload/files/feradujapilurube.pdfIn PDF document text
    • http://ecogestval.es/userfiles/file/tiwogekowilarerojebub.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off00035493.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off00035493.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00035493.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x35493 10392 bytes
SHA-256: e39d5e66a0f061e07740ebc1f429b0a685655a5b1936ab4409afca960006c9a3
font_01_sfnt_off00036c17.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x36C17 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off00038429.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x38429 21904 bytes
SHA-256: 5aeaf0f8f1b8032bf8b72c49c9ee9cd1663076d926eaf55703f52134fcee7438