Malicious PDF — malware analysis report

Static analysis result for SHA-256 634ce507ff0302bc…

MALICIOUS

PDF

764.0 KB Created: 2022-03-24 09:23:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-29
MD5: 56ecbd15ee06c56ed274c5a59beb2da8 SHA-1: b20dd83b821b5e59631ec73e3edb11cacb647067 SHA-256: 634ce507ff0302bcd878fe11b76fbde1da54196c25a3a3beffffdc4a5b6716bc
136 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.1860

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lovig.co.za/XSRYdR1H?utm_term=harry+potter+and+the+prisoner+of+azk PDF link annotation
    • http://corpinal.com/kcfinder/upload/files/wepinus.pdfIn PDF document text
    • https://bahamianbrewery.com/ckfinder/userfiles/files/70458994842.pdfIn PDF document text
    • http://fzcce.com/aimgs/uload/files/96883663700.pdfIn PDF document text
    • https://accuratesearch.com/userfiles/file/jakolamofukobowupafam.pdfIn PDF document text
    • https://www.starvisaservices.co.uk/application/elements/plugins/kcfinder/upload/files/63474937660.pdfIn PDF document text
    • https://finduspeople.it/upload/files/65128316666.pdfIn PDF document text
    • https://rugerwafers.com/demo/ruger/beta/userfiles/files/44340989385.pdfIn PDF document text
    • http://dokumsuzgec.com/userfiles/files/4165803343.pdfIn PDF document text
    • http://ylphs.com/ckfinder/userfiles/files/43727116490.pdfIn PDF document text
    • https://www.horisunmauritius.com/wp-content/plugins/super-forms/uploads/php/files/d2fa749f80c7a00796da12c4f40c6927/49354416928.pdfIn PDF document text
    • http://giacongcomposite.com/upload/ck/files/fezesexupodavexenisawid.pdfIn PDF document text
    • http://lycee-elm.org/userfiles/file/82204461671.pdfIn PDF document text
    • https://berker-rozetki.su/kcfinder/upload/files/71608022859.pdfIn PDF document text
    • http://akatumusics-ang.communication-pro.fr/public/1283/contenu/file/20157079730.pdfIn PDF document text
    • http://www.lovebliss.tw/UserFiles/files/71720558369.pdfIn PDF document text
    • http://www.kliningstroy.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1621245d35d307---miredatatepeguk.pdfIn PDF document text
    • https://sabatti.hu/admin/kcfinder/upload/files/rofixex.pdfIn PDF document text
    • http://chagatea.ru/wp-content/plugins/super-forms/uploads/php/files/a1c9688960b4c54bbbb08be9fd737ad0/36717022130.pdfIn PDF document text
    • http://arnoldbolingbroke.com/ckfinder/userfiles/files/gobowa.pdfIn PDF document text
    • http://armoire-atex.com/js/kcfinder/upload/files/686761010.pdfIn PDF document text
    • https://bnbcostaverde.it/userfiles/file/diwarido.pdfIn PDF document text
    • https://estudiowebcolombia.com/ckfinder/userfiles/files/99572357059.pdfIn PDF document text
    • https://wroclawmodelshow.pl/ckfinder/userfiles/files/22505364447.pdfIn PDF document text
    • https://www.adelaarenergy.com/wp-content/plugins/super-forms/uploads/php/files/sr1m2496qtdksto72jgbhmi0i1/12371186203.pdfIn PDF document text
    • http://www.examnotice.in/uploads/files/61603401938.pdfIn PDF document text
    • https://voskovefiguriny.eu/kcfinder/upload/files/vugatap.pdfIn PDF document text
    • https://www.bluelabs.it/shazar/admin/assets/js/ckeditor/kcfinder/upload/files/files/45698936101.pdfIn PDF document text
    • https://www.darrellstuckey.com/wp-content/plugins/formcraft/file-upload/server/content/files/1620c36a2e7d4c---sipufaxexukazafas.pdfIn PDF document text
    • http://rideco.hu/upload/file/54186333355.pdfIn PDF document text
    • http://www.tamar.org.br/fotos_news/files/didupedekesonajade.pdfIn PDF document text
    • http://ukicda.com/admin/fckeditor_upfiles/file/2022030710191180554.pdfIn PDF document text
    • http://boathousebrokerage.com/userfiles/file/4386710574.pdfIn PDF document text
    • https://nusbetaja2.com/contents/files/50431604398.pdfIn PDF document text
    • https://papersacksfactory.ae/images/bulk_images/files/befajefakowimemepodutuvus.pdfIn PDF document text
    • http://mavelikaradiocese.org/rapha/ckfinder/userfiles/files/gorolivasab.pdfIn PDF document text
    • http://accuway.yun2u.com/upload/files/bitomuvajupukanobiz.pdfIn PDF document text
    • http://gdi-fr.com/upload/upload/18911358444.pdfIn PDF document text
    • http://uzks.hr/upload/datoteke/17726206385.pdfIn PDF document text
    • http://smileorganic.net/smileorgfarm/filesupload/File/43938385594.pdfIn PDF document text
    • http://unstitchedfootwear.net/files/file/13554766558.pdfIn PDF document text
    • https://kgn.pl/files/file/98569497380.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off000b7835.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off000b7835.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000b7835.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB7835 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_01_sfnt_off000b8f55.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB8F55 10808 bytes
SHA-256: f7d1061bbd5374f7574815af7aee06ce1ca6a381240d7e29cff25b70a2f96e45
font_02_sfnt_off000ba838.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBA838 20692 bytes
SHA-256: 4663300567d41d3d0511f4a2b2833eaa02b83894d22602b87096b62620361ba0