Malicious PDF — malware analysis report

Static analysis result for SHA-256 5d38ea9a758314ee…

MALICIOUS

PDF

270.2 KB Created: 2022-03-03 04:56:32 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-14
MD5: 6819b508e57bc60823d7038262dfd365 SHA-1: e61321283dc37196a136a77707483e8761ec3427 SHA-256: 5d38ea9a758314ee0846f9e05aa99d44d3f6821dd57d90caf69f2fca36bd2c90
196 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.6903

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Travel-support phone-number stuffing scam critical SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ragaz.co.za/XSRYdR1H?utm_term=chronic+mastoiditis+pdf PDF link annotation
    • https://pointvirgule.ca/upload/editor/file/xojosutajowid.pdfIn PDF document text
    • http://cravaluos.com/ckfinder/userfiles/files/fibaxosakezaz.pdfIn PDF document text
    • http://c2r.su/uploadfiles/file/2022021805482373499.pdfIn PDF document text
    • http://www.anpamedical.com/kcfinder/upload/files/ninome.pdfIn PDF document text
    • http://chistogood.ru/admin/ckfinder/userfiles/files/80650421291.pdfIn PDF document text
    • https://pnp-studio.com/fckeditorfiles/file/60568866356.pdfIn PDF document text
    • http://dbrostechnology.com.np/dbros/public/ckeditor/kcfinder/upload/files/84373492163.pdfIn PDF document text
    • https://mangonebike.com/uploads/file/29409012101.pdfIn PDF document text
    • https://www.tahi.hu/ckfinder/userfiles/files/11659030803.pdfIn PDF document text
    • http://norilsk.torbay.ru/images/uploads/file/50653532977.pdfIn PDF document text
    • http://www.szphotar.com/admin/img/files/pojetinebanekogev.pdfIn PDF document text
    • https://mtmhomeschool4art.com/mycms/uploadedimages/editorUploadedImages/file/buzonetezojusemaw.pdfIn PDF document text
    • http://auto-berles.oldalunk.hu/userimages/files/kalalemurome.pdfIn PDF document text
    • http://kgpms.org/kcfinder/upload/files/senukamelagevesabowazi.pdfIn PDF document text
    • http://machinegroup.ru/img/outer/files/suzinutawe.pdfIn PDF document text
    • https://vikta-fish.ru/upload/files/satufebuvilole.pdfIn PDF document text
    • http://sb555.com/photo/file/nidexisalipixagarozo.pdfIn PDF document text
    • http://mitrasejati.co.id/assets/kcfinder/upload/files/93232958879.pdfIn PDF document text
    • http://nhuahoanglong.com/luutru/files/14980759348.pdfIn PDF document text
    • http://crm333.com/documentos/file/12014226500.pdfIn PDF document text
    • http://aow.infogestnet.it/ckfinder/userfiles/files/85057432693.pdfIn PDF document text
    • http://pusancard.com/userData/board/file/tagiwuragorazitapal.pdfIn PDF document text
    • https://nisseiplastic.com/up_images/exp/files/45701598067.pdfIn PDF document text
    • https://giverny-bkk.com/upload/files/vazagowetojebufam.pdfIn PDF document text
    • http://7seapharmtech.com/Uploadfiles/files/jamisom.pdfIn PDF document text
    • http://tekizolasyon.com/ckfinder/userfiles/files/zawexukiwitixupe.pdfIn PDF document text
    • http://matchedtubes.de/userfiles/file/lilobigofumu.pdfIn PDF document text
    • https://northwoodsinnsuites.com/nbloom/fckuploads/file/33732867069.pdfIn PDF document text
    • https://leg-vein.jp/kcfinder/upload/files/radobutanepigojuvujo.pdfIn PDF document text
    • http://www.iycadana.org/wp-content/plugins/super-forms/uploads/php/files/qrnuov75kv5fdkhghb21s9fin0/gikuzat.pdfIn PDF document text
    • http://bndweb.nl/upload/files/76323163697.pdfIn PDF document text
    • https://healthmatters.me/userfiles/file/vivumegerozawexugojakofu.pdfIn PDF document text
    • http://strojsteel.cz/webpagebuilder/ckfinder/userfiles/files/fopalasejimipu.pdfIn PDF document text
    • http://ugrctrani.it/userfiles/files/69152507126.pdfIn PDF document text
    • http://theclelandgroup.com/img/upload/file/betowewozebimeme.pdfIn PDF document text
    • http://conflictfreeelectronics.com/ourprojects/chowki/UserFiles/renuka/file/netuwubejewufevejo.pdfIn PDF document text
    • http://haki.vn/uploads/files/rodigagurogobo.pdfIn PDF document text
    • http://1000projects.ru/upload_picture/file/39189618042.pdfIn PDF document text
    • https://xn----8sbaavnccwq4am.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/340813e59b6c21aafdb92aed5d5902ab/59797610898.pdfIn PDF document text
    • http://www.matrixaviationfueling.com/assets/ckeditor/kcfinder/upload/files/tiroxub.pdfIn PDF document text
    • http://szigetkoz-vizitura.hu/admin/kcfinder/upload/files/kawiriviped.pdfIn PDF document text
    • http://lifebeachvilla.com/uploads/image/files/fibojamijogufovez.pdfIn PDF document text
    • http://tamezou.com/upload/ckfinder/files/rekil.pdfIn PDF document text
    • http://studiozammuner.eu/userfiles/files/31896250305.pdfIn PDF document text
    • http://fusen-es.info/yamituki-n/uploads/files/pemejilefumedofogizelisef.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    +4 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0003c90f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3C90F 10740 bytes
SHA-256: 92ef7a8727dc713f36bef54534b49ef30da05dd73f5bf54b515ecf26b3cbf44d
font_01_sfnt_off0003e194.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3E194 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_02_sfnt_off0003f8af.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3F8AF 18284 bytes
SHA-256: cd3c60fa215893d2af454c614ed28c11f1dcc60a06c00ae7e3a12e32b7da895f