Malicious PDF — malware analysis report

Static analysis result for SHA-256 4503b2f20da06e70…

MALICIOUS

PDF

239.7 KB Created: 2022-03-11 04:18:17 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-25
MD5: 394ec4225455610a4efd831486179411 SHA-1: defa1e768a0b83f55d53658bd81818a011b57b04 SHA-256: 4503b2f20da06e7008af97197c85e89877c81a66f7d26b736abb3f9d4972ae95
166 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.7739

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://tevav.co.za/XSRYdR1H?utm_term=abscesso+perianal+pediatria+pdf PDF link annotation
    • http://conservativista.com/js/ckfinder/userfiles/files/xiwipijod.pdfIn PDF document text
    • https://nutritie-metabolism-sanatate.ro/app/webroot/files/userfiles/files/1054966774.pdfIn PDF document text
    • http://fairfresh.net/assets/admin/ckeditorimage/files/90304955243.pdfIn PDF document text
    • http://blackswaninfotech.com/kcfinder/upload/files/sexitafifomonuluketuj.pdfIn PDF document text
    • http://nextgems.com/ckeditor/kcfinder/upload/files/niluxuweviwemuniximinuko.pdfIn PDF document text
    • http://www.beverburcht.nl/upload/files/domibulepa.pdfIn PDF document text
    • https://www.colfacor.org.ar/administrador_web/kcfinder/upload/files/punewunor.pdfIn PDF document text
    • http://rayer.cn/d/files/85122234758.pdfIn PDF document text
    • https://adiwirawanbali.com/wp-content/plugins/super-forms/uploads/php/files/8e5964f831194bdc67ce0ce71b339760/74110123797.pdfIn PDF document text
    • http://www.britocunhaadvocacia.com.br/home/wp-content/plugins/formcraft/file-upload/server/content/files/161fb44e97ff3d---vesiligujaxuvolonefov.pdfIn PDF document text
    • https://qcbusa.com/userfiles/file/zulimuxadula.pdfIn PDF document text
    • https://calprin.com/ckfinder/userfiles/files/11361911602.pdfIn PDF document text
    • https://kristaldicarlo.com/userfiles/file/zowaxowibiwawuji.pdfIn PDF document text
    • http://trivio.it/userfiles/files/91165971573.pdfIn PDF document text
    • http://www.regional4.org.ar/administrador/kcfinder/upload/files/57230167443.pdfIn PDF document text
    • http://otelm4b.ru/admin/ckfinder/userfiles/files/60379546963.pdfIn PDF document text
    • https://serrechevalier-skifun.com/imagesfile/xarisujawupuxabesa.pdfIn PDF document text
    • http://kleinschadenexperte.de/userfiles/file/narobinobudeno.pdfIn PDF document text
    • https://admin.gruppoperonirace.it/kcfinder/upload/files/92222462.pdfIn PDF document text
    • https://www.theoakshealthcare.com/my_content/js/ckfinder/userfiles/files/beropum.pdfIn PDF document text
    • http://www.zulfugar.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1621411317f19b---31883135884.pdfIn PDF document text
    • https://gp-lighting.com/editor_upload/file/53853036277.pdfIn PDF document text
    • http://aire-limpio.com/img/editor/file/kosevu.pdfIn PDF document text
    • https://www.aironface.com/wp-content/plugins/super-forms/uploads/php/files/b2a5374d40bde35b66aba9fdeb6c8164/19743773036.pdfIn PDF document text
    • http://adimhukuk.com/resimler/files/9680413898.pdfIn PDF document text
    • https://transilvaniafishing.ro/app/webroot/files/userfiles/files/23473944042.pdfIn PDF document text
    • http://ikmblansko.cz/files/upload/files/remetuwamevafasarin.pdfIn PDF document text
    • https://esoft.com.bd/assets/ckeditor/kcfinder/upload/files/46050189905.pdfIn PDF document text
    • https://braviengenharia.com.br/wp-content/plugins/super-forms/uploads/php/files/2ghqvnj8mm9lkeno98lkmhs2nv/58300937229.pdfIn PDF document text
    • http://thevisionkharj.com/userfiles/files/30131315247.pdfIn PDF document text
    • https://deewo.de/wp-content/plugins/formcraft/file-upload/server/content/files/161fdedc04c428---gukamusasejox.pdfIn PDF document text
    • https://bloomeng.com/uploads/39302408013.pdfIn PDF document text
    • http://sipzip.com/userfiles/file/66872521121.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0003541c.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0003541c.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0003541c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3541C 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_01_sfnt_off00036b3c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x36B3C 10732 bytes
SHA-256: bf020975918e6f7b86214ae09c09795a11213e2ec41cd07c3fdd8b65c679bf24
font_02_sfnt_off000383c7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x383C7 16856 bytes
SHA-256: 80d79c734c71c1860fc01aa4b40d4e025e76f4414ea14e743ef09acbb1fe4121