Malicious PDF — malware analysis report

Static analysis result for SHA-256 6c68d2e2fece1f74…

MALICIOUS

PDF

325.3 KB Created: 2022-03-06 11:08:51 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-06
MD5: 3f7ed3d0de55bc158543065f048884ff SHA-1: 80c080ae05ab9b803eca21bd714b92411109cf4b SHA-256: 6c68d2e2fece1f7470f439975b918d1767aefab15d94aa2c634edc4188d093c3
166 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.5960

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://sunuf.co.za/XSRYdR1H?utm_term=excel+vba+worksheet+codename+change PDF link annotation
    • https://ertechnikdental.hu/kcfinder/upload/files/teleferivu.pdfIn PDF document text
    • http://westfield.qa/multimedia/userfiles/file/geniteliwabejitofuru.pdfIn PDF document text
    • http://monthclean.com/uploads/files/202202102345043635.pdfIn PDF document text
    • https://messianic.live/wp-content/plugins/super-forms/uploads/php/files/4bf9b43fe94c232b062cb78373f4d413/77270636448.pdfIn PDF document text
    • https://puertoestereo.com/wp-content/plugins/super-forms/uploads/php/files/lf7doe35a5ljkc8un4v95v2pdc/51100092539.pdfIn PDF document text
    • http://dagmar-e.de/userfiles/file/lulitozaru.pdfIn PDF document text
    • http://bitree.net/ckfinder/userfiles/files/tavox.pdfIn PDF document text
    • http://sarica.com.tr/ckfinder/userfiles/files/wukekosewofit.pdfIn PDF document text
    • https://www.akita-tourism.com/assets/admin/plugins/kcfinder/files/dawojoxinejif.pdfIn PDF document text
    • https://euronet.stonavka.cz/webpagebuilder/ckfinder/userfiles/files/jijob.pdfIn PDF document text
    • http://maquetland.com/v2/images_articles2/files/33080235820.pdfIn PDF document text
    • http://kssi.ir/public/userfiles/file/41311402144.pdfIn PDF document text
    • http://oodow.cn/upload/file/220207041848486526zyjr1v4nobb4.pdfIn PDF document text
    • http://callbells.com.ua/kcfinder/upload/files/22843269153.pdfIn PDF document text
    • http://rubensova16.cz/files/file/47573359873.pdfIn PDF document text
    • https://handball-chac.com/docs/file/pulalativajivowowun.pdfIn PDF document text
    • http://a-range.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16205983c3405f---sajawixaraje.pdfIn PDF document text
    • http://sportsclinicwest.ie/media/contents/file/65198641767.pdfIn PDF document text
    • http://michalpavlicek.com/uploaded/file/91560666037.pdfIn PDF document text
    • https://booking-news.hkdnracing.com/webroot/editor-uploads/files/64029377496.pdfIn PDF document text
    • http://m2m2design.com/userfiles/jijumeteraze.pdfIn PDF document text
    • https://cbrn.tj/nrsa_system/ckeditor/kcfinder/upload/files/14685311454.pdfIn PDF document text
    • https://hokusui.co.jp/hsk/wp-content/plugins/ckeditor-for-wordpress/kcfinder/upload/files/tedam.pdfIn PDF document text
    • https://almuhja.ps/ckfinder/userfiles/files/segulo.pdfIn PDF document text
    • http://hardevel.com/data/files/99208083868.pdfIn PDF document text
    • http://goodlack.cz/userfiles/file/8301573729.pdfIn PDF document text
    • http://edallyshop.com/upload/files/55471942359.pdfIn PDF document text
    • https://fceresources.com/ckfinder/userfiles/files/53010879217.pdfIn PDF document text
    • http://taixingchem.com/uploadfile/file/20220215194454534.pdfIn PDF document text
    • http://djapm.com/userfiles/file/24135375984.pdfIn PDF document text
    • http://mikol-styl.cz/userfiles/file/filakefabefadefaziko.pdfIn PDF document text
    • https://www.crosstownnews.in/kcfinder/upload/files/xeliwumofu.pdfIn PDF document text
    • https://sk-developers.com/wp-content/plugins/formcraft/file-upload/server/content/files/1620750c605cb0---lavoxunazajunog.pdfIn PDF document text
    • https://bursakaynak.com/userfiles/file/62136157272.pdfIn PDF document text
    • http://buafit.bg/Uploads/files/84808285646.pdfIn PDF document text
    • http://kartonpier.com/admin/kcfinder/upload/files/1385667113.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off000481d9.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off000481d9.bin)

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000481d9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x481D9 20432 bytes
SHA-256: 314e57bce412bda51b76dae4a4e29f9f5272408aff61ae3f2c558978008ad0d4
font_01_sfnt_off0004b77b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4B77B 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_02_sfnt_off0004ce91.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4CE91 8480 bytes
SHA-256: 44cc87ab97868eb11e91053705c13bf3c86e63b96f0fea91206f6534334874b6
font_03_sfnt_off0004eab7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4EAB7 11192 bytes
SHA-256: e7918c82905af9eefedf5311fd5ff380c6fbbcf5e159dac44ab7e292a5eb28ff