Malicious PDF — malware analysis report

Static analysis result for SHA-256 6d12548e8090cb86…

MALICIOUS

PDF

228.6 KB Created: 2022-05-01 13:48:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-28
MD5: 340e1c4b117b31e089b65ed89ee86b85 SHA-1: e20a1ccc8f819517edc5444f31cb6755e256c62d SHA-256: 6d12548e8090cb860046d3366887ce06c3a3f2b3fd113cd1dc9f23b8f07d115c
166 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.6465

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ragaz.co.za/XSRYdR1H?utm_term=bill+nye+motion+worksheet+free PDF link annotation
    • https://kasalaketowo.weebly.com/uploads/1/3/4/8/134871290/3686713.pdfIn PDF document text
    • http://cmoxgermany.com/upimages/file/16974826648.pdfIn PDF document text
    • https://xuzelete.weebly.com/uploads/1/3/2/6/132681171/tevox_zumaga_wovonunamokes.pdfIn PDF document text
    • https://mojeleku.weebly.com/uploads/1/3/4/8/134862936/jubizapupavubotit.pdfIn PDF document text
    • https://girowotejetut.weebly.com/uploads/1/3/1/4/131406843/4726972.pdfIn PDF document text
    • https://fikepeti.weebly.com/uploads/1/3/4/4/134489659/2748298.pdfIn PDF document text
    • http://p-itos.net/admin/userfile/image/file/poxaguk.pdfIn PDF document text
    • https://vixawesomuwevu.weebly.com/uploads/1/3/5/3/135387162/1630592.pdfIn PDF document text
    • https://rirofogarerena.weebly.com/uploads/1/3/0/7/130775169/dojudafizorigadis.pdfIn PDF document text
    • https://pavaniautismschools.com/wp-content/plugins/super-forms/uploads/php/files/r1p7tn5uvqn603bq70b85ku54s/18917351323.pdfIn PDF document text
    • http://amandatour.ru/js/ckfinder/userfiles/files/31276343908.pdfIn PDF document text
    • https://www.hdod.emed.hr/admin/kcfinder/upload/files/vilugorogunubig.pdfIn PDF document text
    • https://zitujizu.weebly.com/uploads/1/3/4/7/134731650/fatos.pdfIn PDF document text
    • https://ohligschlaeger-berger.de/wp-content/plugins/formcraft/file-upload/server/content/files/1625066b126259---kusov.pdfIn PDF document text
    • http://sfipl.in/userfiles/file/88870637047.pdfIn PDF document text
    • https://destination.irinadempsey.ru/userfiles/file/mukojopitukituwazin.pdfIn PDF document text
    • https://panejukirid.weebly.com/uploads/1/3/1/6/131606092/tumegojabeseseniwamo.pdfIn PDF document text
    • https://sifovepemu.weebly.com/uploads/1/3/4/3/134373157/naxidalakubalisowo.pdfIn PDF document text
    • https://gokuxevi.weebly.com/uploads/1/3/4/0/134017514/8a34e35b7b.pdfIn PDF document text
    • http://dangkyidol.com/wp-content/plugins/super-forms/uploads/php/files/88lh5qvj6i9e89970ljknfbknj/wutodunototoz.pdfIn PDF document text
    • https://mapobosani.weebly.com/uploads/1/3/4/3/134385232/nexopetixusuwu.pdfIn PDF document text
    • https://kevititexozasen.weebly.com/uploads/1/3/2/7/132712545/7322959.pdfIn PDF document text
    • https://nulokumex.weebly.com/uploads/1/3/3/9/133999188/famew_komuw.pdfIn PDF document text
    • https://julogunakununu.weebly.com/uploads/1/3/2/8/132814048/fanedafatodumov.pdfIn PDF document text
    • https://jiwejezagaxu.weebly.com/uploads/1/3/5/3/135325467/59edd507140ff80.pdfIn PDF document text
    • https://cap2013.aseat.fr/userfiles/file/13392560090.pdfIn PDF document text
    • https://laxefozono.weebly.com/uploads/1/3/4/3/134361517/3d20fb1a6.pdfIn PDF document text
    • https://lumidenozure.weebly.com/uploads/1/3/5/3/135345408/1527306.pdfIn PDF document text
    • https://jupimoxojufe.weebly.com/uploads/1/3/4/8/134860775/mufuguvunosisud-levogoso-kezilipixevivom.pdfIn PDF document text
    • https://hawkseyetravels.com/assets/ckfinder/userfiles/files/24602443809.pdfIn PDF document text
    • http://chpcentre.com/files/file/70721040412.pdfIn PDF document text
    • http://e-sheremet.com/img/71149342869.pdfIn PDF document text
    • https://watoniworawi.weebly.com/uploads/1/3/4/8/134871767/rozagavupabanin_memul_tugazowom_dunovo.pdfIn PDF document text
    • https://widegavadiwudux.weebly.com/uploads/1/3/5/3/135325068/metusujeneli.pdfIn PDF document text
    • https://luzatewuxajexi.weebly.com/uploads/1/3/4/2/134265782/6187589.pdfIn PDF document text
    • https://batovidurasitoz.weebly.com/uploads/1/3/4/3/134340050/wamakaj.pdfIn PDF document text
    • https://mamap.in/ci/userfiles/files/nitukavof.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off00032469.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off00032469.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00032469.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x32469 16864 bytes
SHA-256: 3b39698ff7c14579ce3a7b66d8fe9984d40f2c40460e36506fc5c794550c53b8
font_01_sfnt_off0003502b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3502B 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off00036842.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x36842 10660 bytes
SHA-256: 5db4b9dc8fb9c14dfc4fad2239926e3a165234228b52d3a33ec578611f9a4b69