Malicious PDF — malware analysis report

Static analysis result for SHA-256 63490295bcb10d4b…

MALICIOUS

PDF

178.3 KB Created: 2022-02-24 21:55:41 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-28
MD5: 3fa2e72b3cafb5ebaaf6c14278e91470 SHA-1: d0fe2c65932f3c8754695341823f4607f38c1ade SHA-256: 63490295bcb10d4b19110ecfa631126157bfe15422a8e35ab717c64e472942d4
156 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.6928

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dangeloremodeling.com/nbloom/fckuploads/file/kixum.pdf In PDF document text
    • http://oneself.pro/wp-content/plugins/formcraft/file-upload/server/content/files/161dc7433d4e2a---17451432421.pdfIn PDF document text
    • http://ecogestval.com/userfiles/file/geremafogevupi.pdfIn PDF document text
    • https://www.pferde-fuer-unsere-kinder.de/wp-content/plugins/formcraft/file-upload/server/content/files/161b7065e9d4eb---valerosejejutifopi.pdfIn PDF document text
    • https://4taif.com/userfiles/file/98818342550.pdfIn PDF document text
    • http://architettomontanino.eu/userfiles/files/kadezeku.pdfIn PDF document text
    • http://jfhcoaching.com/userfiles/files/71210433249.pdfIn PDF document text
    • https://projetovm.com/uploads/files/23750333279.pdfIn PDF document text
    • http://www.alm-machines.be/kcfinder/upload/files/92207903448.pdfIn PDF document text
    • http://techscreening.com/userfiles/files/gogotuvuwuzonixuwunuji.pdfIn PDF document text
    • https://marlin-shop.ru/ckfinder/userfiles/files/45579605972.pdfIn PDF document text
    • http://xn--ob0bjxt9h99icicrvkksa421cwwp7hiv4d6a.net/ckfinder/userfiles/files/33488483810.pdfIn PDF document text
    • https://aznamaste.com/ckfinder/userfiles/files/dujimuwefoduv.pdfIn PDF document text
    • https://blgjad.com/upload/files/xinamod.pdfIn PDF document text
    • http://sahcarpets.com/userfiles/file/46228782862.pdfIn PDF document text
    • https://strechybenesov.cz/content/46779655809.pdfIn PDF document text
    • http://whuntex.ru/userfiles/file/titekubadebo.pdfIn PDF document text
    • http://farmaciafici.com/userfiles/files/31411390202.pdfIn PDF document text
    • http://qiangka.com/ckfinder/userfiles/files/52500875186.pdfIn PDF document text
    • http://xn--b1adbbbaeqjtsflbfms0e.xn--p1ai/pict/file/lebasineziwe.pdfIn PDF document text
    • http://wellcomm.co.id/assets/kcfinder/upload/files/gibamukezasuguligelab.pdfIn PDF document text
    • http://auroraenergyproject.it/userfiles/files/26253213950.pdfIn PDF document text
    • https://olterus.info/contents/files/poresuwerumipan.pdfIn PDF document text
    • http://www.lasallelille.com/admin/ckfinder/userfiles/files/timeliju.pdfIn PDF document text
    • http://yuhenganquan.com/userfiles/file/20210702013827_1760411948.pdfIn PDF document text
    • http://rakkhunnursinghome.com/user_img/files/bubiwinegumizaraj.pdfIn PDF document text
    • https://beautyyaurient.com/editor_upload/file/9194410486.pdfIn PDF document text
    • http://nuk-amro.de/userfiles/file/57302733819.pdfIn PDF document text
    • https://actionalbertafoundationrepair.com/nbloom/fckuploads/file/39212361411.pdfIn PDF document text
    • https://bizdrive.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1/16132e0b45b35e---subopas.pdfIn PDF document text
    • https://monarchwinemerchants.com/wp-content/plugins/super-forms/uploads/php/files/a84c69ce4f4385fe172343114effa150/totugexoxin.pdfIn PDF document text
    • https://posaonakosovu.com/ckfinder/userfiles/files/92065103039.pdfIn PDF document text
    • http://anantasandesh.com/dbros/public/ckeditor/kcfinder/upload/files/jobifa.pdfIn PDF document text
    • https://adium.ru/userfiles/file/pikazup.pdfIn PDF document text
    • http://www.inhd.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16197afc758549---95983256579.pdfIn PDF document text
    • https://cashcruis.ru/wp-content/plugins/super-forms/uploads/php/files/847396593bb64afd3828fd77a163b0f1/17904313223.pdfIn PDF document text
    • http://kstarsmall.net/userfiles/file///10382169328.pdfIn PDF document text
    • https://studiogreenwich.ru/wp-content/plugins/super-forms/uploads/php/files/55ada61b6b8bb4a7a9b32f6b3daac675/guxov.pdfIn PDF document text
    • http://nuraski.pl/wsg/userfiles/87871273707.pdfIn PDF document text
    • https://loheb.co.za/XSRYdR1H?utm_term=enfermedades+que+causa+el+sedentarismo+pdfPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off00025216.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off00025216.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00025216.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x25216 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_01_sfnt_off00026936.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x26936 11008 bytes
SHA-256: 275aba27d386abfb9f7494b88ede474be7792b4e01be8bd46bbe3396e46d4256
font_02_sfnt_off0002828d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2828D 21128 bytes
SHA-256: 2a7ccfda727286eca850a01c39da1fd16ae62089a5716c3bf954e15afdeae8db