Malicious PDF — malware analysis report

Static analysis result for SHA-256 45004cd883461b6f…

MALICIOUS

PDF

221.5 KB Created: 2022-03-13 15:01:14 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-25
MD5: 87b8db2aedc1cd622f3709e82b173dc2 SHA-1: 1066b261f0e0e4a6a0c36c22fd2e66d72dc726f9 SHA-256: 45004cd883461b6f0356b0ed23271fafacb78cb029166fc22f1de17e674da5a4
166 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.7780

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://tevav.co.za/XSRYdR1H?utm_term=msdn+sql+server+2014+developer PDF link annotation
    • http://techmechengineers.com/uploads/vetogojeruj.pdfIn PDF document text
    • http://media-production.net/admin/ckfinder/userfiles/files/1018641799.pdfIn PDF document text
    • https://vectronic.tech/admin/ckeditor/kcfinder/upload/files/fulameloredimupa.pdfIn PDF document text
    • http://narcisse.sk/editor_uploads/files/60469141835.pdfIn PDF document text
    • http://valdhans.cz/userfiles/file/38502990758.pdfIn PDF document text
    • https://www.democratum.com/wp-content/plugins/super-forms/uploads/php/files/e1e3f64ec2484194816b74e1bb005e2c/jasewokosigobusaxinix.pdfIn PDF document text
    • http://farmaciacogliate.it/userfiles/files/kipoxaganusin.pdfIn PDF document text
    • http://muzeumostrowiec.pl/obrazy/file/28156769629.pdfIn PDF document text
    • https://eastmangroup.org/ckfinder/userfiles/files/zarugilisa.pdfIn PDF document text
    • https://odontologosmalca.com/images/userfiles/file/56222915994.pdfIn PDF document text
    • http://tai-group.com/upload/files/88453257019.pdfIn PDF document text
    • http://webminmax.com/userfiles/file/josij.pdfIn PDF document text
    • http://spiregene.com/image/files/20220221_130007.pdfIn PDF document text
    • https://tramincojp.com/uploads/news_file/tonegazunij.pdfIn PDF document text
    • https://rugsdirect4u.com/uploadedfiles/file/derar.pdfIn PDF document text
    • https://centar-znr-zop.hr/wp-content/plugins/formcraft/file-upload/server/content/files/16227a5b11a862---razipu.pdfIn PDF document text
    • https://semangkamerah.com/contents/files/famokatimewusivixilub.pdfIn PDF document text
    • http://egyptfuture-eg.com/public/kcfinder/upload/files/folezusaj.pdfIn PDF document text
    • http://yule-sign.com/upload/editor/file/20220310034631.pdfIn PDF document text
    • https://klcmekatronik.com/ckfinder/userfiles/files/34800082610.pdfIn PDF document text
    • http://canlook.ru/userfiles/files/lodojenemedezanilipar.pdfIn PDF document text
    • http://operahazyborlovagok.hu/browser/files/55065132449.pdfIn PDF document text
    • https://ductlessheating.ca/fck_upload/file/mivakiniporipegosuvibikus.pdfIn PDF document text
    • https://cowichanseniors.ca/userfiles/file/78065324038.pdfIn PDF document text
    • http://automsystem.com/UploadFile/file/20220224153121873.pdfIn PDF document text
    • http://malir-naterac.info/UserFiles/File/69029556406.pdfIn PDF document text
    • http://yuseigachi.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1622c1d4faa810---12049711062.pdfIn PDF document text
    • https://ijfbacknumber.com/editor_up/dapukepejaziramip.pdfIn PDF document text
    • http://nhakhoanhantin.com/media/ftp/file/14320413159.pdfIn PDF document text
    • http://healingtown.org/userData/board/file/ripip.pdfIn PDF document text
    • https://bentzendesign.se/wp-content/plugins/formcraft/file-upload/server/content/files/1620d76456fb90---68657764372.pdfIn PDF document text
    • https://www.blackandwhite-salon.com/wp-content/plugins/super-forms/uploads/php/files/69a4620d8e6e9f0ed75174c1d4cf77f0/25889214403.pdfIn PDF document text
    • http://kommunikator.nu/demo/userfiles/file///73830538080.pdfIn PDF document text
    • https://unique-u.biz/images/uploads/file/24373372948.pdfIn PDF document text
    • http://tythb.cn/uploadfile/files/45465924490.pdfIn PDF document text
    • http://vom-ragnaroek.de/uploads/file/peduxoxilemexigobi.pdfIn PDF document text
    • https://paixaodecristopi.cinemadossertoes.com/kcfinder/files/vulemaj.pdfIn PDF document text
    • http://metalzilembo.it/userfiles/files/libajubakadoluworazedef.pdfIn PDF document text
    • https://kuzeyilac.com/resimler/files/44169416710.pdfIn PDF document text
    • https://firstview.christoff-design.com/files/lizuzezabajejalikikifasa.pdfIn PDF document text
    • http://tdsns.ru/userfiles/file/jidaxejixetupofawutide.pdfIn PDF document text
    • https://adasms.fr/userfiles/file/27406053863.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off000305b7.bin)
    +1 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000305b7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x305B7 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_01_sfnt_off00031cd2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x31CD2 18528 bytes
SHA-256: 059a85ea90fafa4f2646332c4a00f7346a49b05ff520020a0884ae79aa744228
font_02_sfnt_off00034d88.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x34D88 10608 bytes
SHA-256: dd8e6b3e041d17b0f4e50fd3dc9097c39ff05733d00fa667a29f325f0b1c94b2