Malicious PDF — malware analysis report

Static analysis result for SHA-256 6dfff0b8b6c189d8…

MALICIOUS

PDF

358.6 KB Created: 2022-02-08 11:58:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-18
MD5: bd04806643bccb2066d3602b0aaa76d9 SHA-1: fc3f345b635f6db6bf6ca6e484085ac924889982 SHA-256: 6dfff0b8b6c189d8bf061fdeff18dc0a562c6186ce459e8d5b928ee016075813
166 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.6817

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yubit.co.za/XSRYdR1H?utm_term=lutheran+church+of+the+reformation+rochester+ny PDF link annotation
    • http://www.coverseg.com/uploads/ckfinder/files/20274960909.pdfIn PDF document text
    • http://valburysekuritas.co.id/upload/files/16620718534.pdfIn PDF document text
    • http://think6.net/ckfinder/userfiles/files/20220110182949.pdfIn PDF document text
    • https://yam-token.com/business_school/uploads/file/55900187967.pdfIn PDF document text
    • https://etest.vn/app/webroot/uploads/files/rasanufalitoga.pdfIn PDF document text
    • http://xboxheerlen.nl/userfiles/file/fosozukatute.pdfIn PDF document text
    • http://kapfenberger-schuetzenverein.at/userfiles/file/tudese.pdfIn PDF document text
    • http://forsheda.se/admin/kcfinder/upload/files/84691723009.pdfIn PDF document text
    • http://www.masozilina.sk/ckfinder/userfiles/files/lejofurutelepenufigavoba.pdfIn PDF document text
    • http://garagehayashi.com/js/upload/files/59016492197.pdfIn PDF document text
    • http://divelife.kz/files/file/kenijujozetumozosose.pdfIn PDF document text
    • https://www.corpeverest.com/ckfinder/userfiles/files/17382484936.pdfIn PDF document text
    • http://pibar.tw/uploads/files/202109221918374107.pdfIn PDF document text
    • http://degeninhotel.ru/admin/ckfinder/userfiles/files/nubotufebuma.pdfIn PDF document text
    • http://cutskytools.com/d/files/kepodonimodu.pdfIn PDF document text
    • https://biomisszio.hu/tmp/xatirijuxemebuzimexoxag.pdfIn PDF document text
    • https://www.webhisto.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16144736e061b0---17300430707.pdfIn PDF document text
    • https://www.liad-alger.fr/admin/style/js/edit/kcfinder/..%5Cimages%5Ccontenue/files/83436210746.pdfIn PDF document text
    • http://ilovegabal.net/fckeditor/_upload/file/78208222293.pdfIn PDF document text
    • http://18554080.com/userfiles/file/gepemabolowelexuzabe.pdfIn PDF document text
    • http://www.pattyn360.com/upload/forum/files/28822994582.pdfIn PDF document text
    • https://www.gs-gleichmann.de/wp-content/plugins/formcraft/file-upload/server/content/files/16128f20f0dcb7---nanom.pdfIn PDF document text
    • http://godsownproperties.com/userfiles/file/39488203154.pdfIn PDF document text
    • http://www.atad.ae/emanager/assets/ckeditor/plugins/kcfinder/upload/files/66493645706.pdfIn PDF document text
    • https://edusfera.pl/upload/file/59949128486.pdfIn PDF document text
    • http://specel.kz/app/webroot/js/kcfinder/upload/files/82513185133.pdfIn PDF document text
    • http://mlsy.cz/images/file/files/tovolovufanetugade.pdfIn PDF document text
    • http://jodhpurheritagewalk.com/images/file/24416054934.pdfIn PDF document text
    • https://beleznayauto.hu/galeria/pictures/nogomarujananilojedi.pdfIn PDF document text
    • https://www.davidcosz.de/wp-content/plugins/super-forms/uploads/php/files/ql8ou7du5nak2rvm98mrq9vbm3/xiroradanekidiwov.pdfIn PDF document text
    • https://vildmarksjagt.dk/userfiles/file/3300065398.pdfIn PDF document text
    • https://schreinerheusi.de/wp-content/plugins/formcraft/file-upload/server/content/files/161f06b0b576eb---36004506406.pdfIn PDF document text
    • http://baloneacessorios.com/_upload/file///sumemodowamelesimevuso.pdfIn PDF document text
    • http://hkxhjfc.ltd/uploads/files/20210827201830.pdfIn PDF document text
    • http://parquet-cortes.fr/data/Files/52717439828.pdfIn PDF document text
    • https://mountainbrookbuilders.com/home/mountain/public_html/ckfinder/userfiles/files/4774695335.pdfIn PDF document text
    • http://brackenpaving.com/files/7655445627.pdfIn PDF document text
    • http://americusfelderfamily.com/clients/0/0c/0c5e5e27a4da9db51eb23c24aa0fa274/File/39736201787.pdfIn PDF document text
    • https://www.medicalart.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16186fd0109b2a---zoralanu.pdfIn PDF document text
    • http://imailbox.nl/images/uploadedimages/file/nagizas.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0005246d.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0005246d.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0005246d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5246D 20296 bytes
SHA-256: 2698ac943102011e717940ee162e26ca2906225870df7c1dfd160a0d3cb7c67a
font_01_sfnt_off00055a78.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x55A78 10724 bytes
SHA-256: b9a73a9168f370cf2d8d0dbbae0951d8651afc852870d78880909207565d36e3
font_02_sfnt_off00057301.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x57301 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9