Malicious PDF — malware analysis report

Static analysis result for SHA-256 5f3865809bd1c008…

MALICIOUS

PDF

363.1 KB Created: 2022-02-25 19:04:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-03
MD5: 7d280bf0e7825807988e8c0201f7d589 SHA-1: 0098f5fd2092bf8448a48a9d6f0f70a6ac64ea25 SHA-256: 5f3865809bd1c008adf0c3aa24d49cd56dd435818b0d52a2c5c6c7076b531baa
136 Risk Score

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4823

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mifuj.co.za/XSRYdR1H?utm_term=adidas+footwear+size+guide PDF link annotation
    • http://neurooperations.com/ckfinder/userfiles/files/zerimebogolojebubojiwavot.pdfIn PDF document text
    • http://tzsunup.com/upload/971007417.pdfIn PDF document text
    • https://nhanloc.net/userfiles/file/64360360142.pdfIn PDF document text
    • https://nguoixunghekiev.vn/userfiles/file/23016301120.pdfIn PDF document text
    • http://www.lbf-cosmetics.com/website/wp-content/plugins/formcraft/file-upload/server/content/files/1615d3d0f72b6b---47663143106.pdfIn PDF document text
    • http://www.trimbleexpress.sk/wp-content/plugins/formcraft/file-upload/server/content/files/16115b5ef1e7a2---derusipuzejaburetov.pdfIn PDF document text
    • https://chasehr.in/userfiles/file/gexakuloxawo.pdfIn PDF document text
    • https://ngusacdon.com/upload/files/58988596151.pdfIn PDF document text
    • http://abcbyspu.com/ckfinder/images_store/files/pamuwox.pdfIn PDF document text
    • http://modernplating.com/userfiles/file/35395714012.pdfIn PDF document text
    • https://rhythmcprandfirstaid.com/wp-content/plugins/super-forms/uploads/php/files/18a49fb8f6fdb5f22f52eefc51a59426/tomitowuru.pdfIn PDF document text
    • http://www.kocay.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/161ea899af0105---72420770698.pdfIn PDF document text
    • http://solmoda.it/userfiles/files/12451475942.pdfIn PDF document text
    • http://hodgesmageefamilyreunion.com/clients/c/c9/c95619ca3ec29dd030dc8935b97378d4/File/58098172401.pdfIn PDF document text
    • https://heritran.vn/uploads/news_file/7311591579.pdfIn PDF document text
    • http://f-okinawa.com/img/tmp/files/tagelitisebafudep.pdfIn PDF document text
    • https://jdrum-music.com/uploads/ckfiles/files/voluwixikemusorokixeko.pdfIn PDF document text
    • http://kleinschadenexpert.com/userfiles/file/laladapozafavolebarujedu.pdfIn PDF document text
    • http://clinical-pain.com/pds/userfiles/files/33819096571.pdfIn PDF document text
    • http://famcareconnect.org/wp-content/plugins/formcraft/file-upload/server/content/files/1610fe6f0a427f---tomubilisugudizasakapa.pdfIn PDF document text
    • https://www.hagensmarketing.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613796c55e4ca---ribametabinanuwimelanuta.pdfIn PDF document text
    • http://commsoft.nu/demo/ktb/wsmbilder/files/rokezokudatafazoxume.pdfIn PDF document text
    • http://newgrids.com/userfiles/file/97356929380.pdfIn PDF document text
    • http://www.hcibatiment.fr/wp-content/plugins/formcraft/file-upload/server/content/files/161d06b0ba3ba7---66829531044.pdfIn PDF document text
    • http://xy-interior.com/uploads/files/202111230851516150.pdfIn PDF document text
    • http://koreapyogo.puruemi.com/userData/affis_board/file/72657848571.pdfIn PDF document text
    • http://bergfin.se/wp-content/plugins/formcraft/file-upload/server/content/files/160ec5141bbb11---63908016942.pdfIn PDF document text
    • http://vcelari.naceradec.cz/includes/ckfinder/userfiles/files/79130092350.pdfIn PDF document text
    • https://abaray.foliopic.com/dinutikifusizupilekope.pdfIn PDF document text
    • http://frigotechreina.com/userfiles/files/69321725092.pdfIn PDF document text
    • https://arizonapoolcontractor.com/wp-content/plugins/formcraft/file-upload/server/content/files/161a069895512d---gilikubemajotuwo.pdfIn PDF document text
    • http://corising.info/sa_upload/userfiles/file/20210807011150.pdfIn PDF document text
    • http://reklama-v-sochi.com/ckfinder/userfiles/files/sokab.pdfIn PDF document text
    • https://ajitcoatings.com/uploads/72507945524.pdfIn PDF document text
    • http://openendrep.com/userfiles/files/316662130.pdfIn PDF document text
    • https://ecef-groupe.com/wp-content/plugins/super-forms/uploads/php/files/lols9oc9hsohqaublcel3u54f1/dozutiwixamival.pdfIn PDF document text
    • https://newat.ru/wp-content/plugins/super-forms/uploads/php/files/8c428f957a6500367136dba9f58d4655/gotavivuwemufibijisedix.pdfIn PDF document text
    • http://hbaoge.com/upload/files/wobozigu.pdfIn PDF document text
    • http://www.mvdisposal.com/wp-content/plugins/formcraft/file-upload/server/content/files/160e62ab8b5af5---70483326361.pdfIn PDF document text
    • http://sibmaxi.ru/userfiles/file/3127010729.pdfIn PDF document text
    • http://asclyziarskyklub.sk/userfiles/file/webabobifegaviwobexazexiw.pdfIn PDF document text
    • http://atlonnuri.org/UpLoadImage/editer/files/83017500892.pdfIn PDF document text
    • http://www.whirlpool-beachcomber.at/wp-content/plugins/formcraft/file-upload/server/content/files/161b4d81078f4f---simadubowevorubenikox.pdfIn PDF document text
    • https://centrehistoriquesndbc.com/ckfinder/userfiles/files/pebaseferosuvegugasu.pdfIn PDF document text
    • http://quranday.org/userfiles/file/20414939685.pdfIn PDF document text
    • http://savitaco.com/uploads/images/files/99013406810.pdfIn PDF document text
    • http://mea-travel.pl/userfiles/file/pizukifogole.pdfIn PDF document text
    • https://www.coopi.org/admin/assets/js/ckeditor/kcfinder/upload/files/files/27132127936.pdfIn PDF document text
    • http://eastendmediation.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/87572027309.pdfIn PDF document text
    +10 more URL(s)

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0005230f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5230F 16336 bytes
SHA-256: adf38969d40f501586e0caf93d33991e243baeeecfe575c4831cdbf64b7044fa
font_01_sfnt_off00053916.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x53916 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_02_sfnt_off0005503d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5503D 18932 bytes
SHA-256: ae176e67df5da4bc9477106f3509bc3e851fa40d3bf4afb16741ffb8b7d1a130
font_03_sfnt_off00058291.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x58291 10608 bytes
SHA-256: 9f398ba443688b46ae8bdd4e9edf7e5db9f8ca63f95c10349e5ebfddc351ff14