Malicious PDF — malware analysis report

Static analysis result for SHA-256 588175e46370f21d…

MALICIOUS

PDF

281.8 KB Created: 2022-04-15 08:54:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-24
MD5: 5c5c285fb9abeae41c92e6083937a1ce SHA-1: c41ed5a9e845a3611294796cdde0fbe3d612214b SHA-256: 588175e46370f21ddc4fe0ee5d298417410a5e151829b88703605402c8e88d11
136 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.7430

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://podar.co.za/XSRYdR1H?utm_term=arcos+dorados+holdings+inc+annual+report+2017 PDF link annotation
    • http://globalroomplus.com/bot/ckfinder/uf/files/molifuke.pdfIn PDF document text
    • http://studioschicchi.eu/userfiles/files/pojinifamaremega.pdfIn PDF document text
    • https://www.medicalbi.com/ckfinder/userfiles/files/99492585019.pdfIn PDF document text
    • https://skvacations.com/userfiles/file/19779586655.pdfIn PDF document text
    • https://nitevugumosu.weebly.com/uploads/1/3/4/5/134526644/dorajomodilexom_dotamuxegolo_fujamegizujus_waxisisiwenatot.pdfIn PDF document text
    • https://dosedoduni.weebly.com/uploads/1/3/4/3/134347632/wuvudubonatinojupepu.pdfIn PDF document text
    • http://kuwaited.com/cote_dor_import/admin/ckfinder/userfiles/files/fokusobarizek.pdfIn PDF document text
    • http://kayamedbursa.com/userfiles/file/76436739322.pdfIn PDF document text
    • http://domuran.pl/files/file/siwezajipaverafukamaferit.pdfIn PDF document text
    • https://jasemoluzisad.weebly.com/uploads/1/3/5/9/135968146/7331533.pdfIn PDF document text
    • http://immodraft.eu/images/architekten_agentur_images_/file/jugavegorotelaralutete.pdfIn PDF document text
    • https://xipinirobidojuv.weebly.com/uploads/1/3/4/0/134017625/fedizenumozova.pdfIn PDF document text
    • http://t-eamplus.de/web/editor/files/82425859300.pdfIn PDF document text
    • http://flirtproducties.nl/ckfinder/userfiles/files/93835730946.pdfIn PDF document text
    • https://palaragas.weebly.com/uploads/1/4/1/3/141364523/3dd44a2993523a.pdfIn PDF document text
    • https://prestinireedcorp.com/userfiles/files/43977336228.pdfIn PDF document text
    • http://fantasymusic.it/userfiles/files/wenofesiketiropesusirovo.pdfIn PDF document text
    • https://greshamgilessalon.com/wp-content/plugins/super-forms/uploads/php/files/ef03308faa0817a73c631e18c9863e8e/25183430654.pdfIn PDF document text
    • https://viwifigejemi.weebly.com/uploads/1/3/0/8/130814408/8270471.pdfIn PDF document text
    • http://e68momo.com/shopadmin/upload/files/nevijejebelatavanesuf.pdfIn PDF document text
    • https://needletherapy.eu/upload/file/18507849100.pdfIn PDF document text
    • https://lavafijaxeb.weebly.com/uploads/1/3/0/7/130740432/251111.pdfIn PDF document text
    • http://leeclinic.kr/userData/board/file/79565083395.pdfIn PDF document text
    • http://www.pethouse.es/ckfinder/userfiles/files/58044384825.pdfIn PDF document text
    • https://puwikopigab.weebly.com/uploads/1/3/1/1/131163601/juleba_porizifinikupex.pdfIn PDF document text
    • https://xomivumikeso.weebly.com/uploads/1/3/0/7/130774979/xitozu.pdfIn PDF document text
    • http://melvin.cz/data/suwiwavimizix.pdfIn PDF document text
    • http://slhospital.com/upload/fckeditor/file/fuposuperixuza.pdfIn PDF document text
    • https://sabiwivilo.weebly.com/uploads/1/3/4/3/134316676/zaxokaneketalak_lanonuvuko_rifebakexozoto.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0003fe2d.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0003fe2d.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0003fe2d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3FE2D 11220 bytes
SHA-256: 6b3b9ce0789a28a180f1595216574b2fd879f31e686ddf35a3dc58e33a5bf0a9
font_01_sfnt_off00041850.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x41850 15420 bytes
SHA-256: 38601b5087aa10da8f508847dde7f481e7dca1d6cf8e4561eae28fe33268412f
font_02_sfnt_off00043fa8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x43FA8 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1