Malicious PDF — malware analysis report

Static analysis result for SHA-256 550dec1a418e4727…

MALICIOUS

PDF

437.6 KB Created: 2022-01-02 05:51:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-04
MD5: 7e3c595702c597664e6509f3ab3b21b5 SHA-1: 410fa5589c6845b61a49a1a23824bfda82e4116b SHA-256: 550dec1a418e47270190a2e82c8265994c01e17432d379e0b66fc4dda9213985
194 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.5836

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ketchas.ru/uplcv?utm_term=alimentos+que+contienen+vitamina+d+pdf In PDF document text
    • https://frmf.merkafoot.com/stock/file/7899635353.pdfIn PDF document text
    • https://pastravariaizvoarelebratiei.ro/images/file/pimedazafunaboputuk.pdfIn PDF document text
    • http://securite.paqt.fr/images/file/10852078359.pdfIn PDF document text
    • https://synodradomski.pl/userfiles/file/farogakoseduz.pdfIn PDF document text
    • https://interstudy.net/userfiles/file/lafikenoda.pdfIn PDF document text
    • https://www.casestilistas.es/ckfinder/userfiles/files/rararo.pdfIn PDF document text
    • https://www.emmabowman.com/wp-content/plugins/super-forms/uploads/php/files/2ef23517bf1b32b73cfaa56d877e6970/toranapagifikaberoveni.pdfIn PDF document text
    • http://daegyung.kr/userfiles/file/20210920123251.pdfIn PDF document text
    • https://cityface.cz/res/file/97542614431.pdfIn PDF document text
    • http://kaie.org/userfiles/file/20211202094254.pdfIn PDF document text
    • https://www.tyrtaios.gr/ckfinder/userfiles/files/bogupopo.pdfIn PDF document text
    • http://studiorestagno.eu/userfiles/files/geriberej.pdfIn PDF document text
    • https://aimtronu.org/userfiles/file/31912285910.pdfIn PDF document text
    • http://klemanpince.hu/files/file/lukud.pdfIn PDF document text
    • http://hcm-invoice.vn/hinhanh_fckeditor/file/morazenonuzez.pdfIn PDF document text
    • http://nesemlak.com/test/images/uploads/files/71000642821.pdfIn PDF document text
    • https://iamluno.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613a0665d334a---buxujokexafo.pdfIn PDF document text
    • https://dennismaloney.ca/upload/editor/file/31447847487.pdfIn PDF document text
    • https://laurallo.com/ckfinder/userfiles/files/bozijajijode.pdfIn PDF document text
    • http://renknh.com/ckupload/files/bepozinoguwaxoje.pdfIn PDF document text
    • https://bczenekar.hu/files/file/sategemofuge.pdfIn PDF document text
    • https://faresaldabbous.com/uploads/files/jalaliworulido.pdfIn PDF document text
    • http://lnimeina.it/userfiles/files/36232065403.pdfIn PDF document text
    • https://nstoplana.rs/ckfinder/userfiles/files/tewemabowimonutew.pdfIn PDF document text
    • https://studiecarriere.it/uploads/file/duzolupegiritepisarimesuf.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off00065d27.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off00065d27.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00065d27.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x65D27 10972 bytes
SHA-256: 37506d604f6455632feee638c80816240263c4d8911c231fe1ccc7b89b30a1c9
font_01_sfnt_off00067673.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x67673 16416 bytes
SHA-256: cfa2c3fbce80cc5607e01af033b793d17c57c214fb1d96e845eedea48cccd336
font_02_sfnt_off00068d12.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x68D12 23532 bytes
SHA-256: bac1d77ccad0cc84c4854feba6c727421ae74284511adeb8f105dc570a2d43b0