Malicious PDF — malware analysis report

Static analysis result for SHA-256 6f3bfc985fcca755…

MALICIOUS

PDF

271.4 KB Created: 2022-05-08 20:52:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-25
MD5: fad54683d72dd487de90d6b0ab14fcb1 SHA-1: 84ae0f2a3b1c7affeb1dc92aa60582466fee6050 SHA-256: 6f3bfc985fcca7557ba874ee14020132ea8a397ef57049d7ae9a8ca4d5fe8bbb
236 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.6013

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Brand-impersonation credential phishing lure critical SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: action link to abused redirector https://dejizova.weebly.com/uploads/1/3/3/9/133986792/motonozunufeje.pdf.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Government-agency impersonation credential phishing lure high SE_GOV_CREDENTIAL_PHISH
    Document impersonates a government agency (Social Security, IRS, Medicare, HMRC, etc.) and uses identity/benefits-verification coercion ('identity verification required', 'this review is mandatory', 'temporary account restrictions') to steer the reader to a link that is not an official .gov/.mil destination — the hallmark of a benefits/identity credential-harvesting lure.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ragaz.co.za/XSRYdR1H?utm_term=the+mom+test+free+pdf+file+online+editor PDF link annotation
    • https://bodzlomu.com/userfiles/file/mevaxirumivizapesibiji.pdfIn PDF document text
    • https://dejizova.weebly.com/uploads/1/3/3/9/133986792/motonozunufeje.pdfIn PDF document text
    • http://chmer.yun2u.com/upload/files/47846477831.pdfIn PDF document text
    • http://studiotecnicomaglio.it/userfiles/files/sezitarevadenetezip.pdfIn PDF document text
    • https://josadezabo.weebly.com/uploads/1/3/4/4/134490641/caa1e29545b96.pdfIn PDF document text
    • http://shengyaweb.com/uploadfile/file/2022022522154625.pdfIn PDF document text
    • https://privatdaniela.sk/upload/files/27995809583.pdfIn PDF document text
    • https://newomuzupigew.weebly.com/uploads/1/3/4/4/134468212/d5861f03b103.pdfIn PDF document text
    • https://xuwukixirekut.weebly.com/uploads/1/3/5/9/135966502/6476749.pdfIn PDF document text
    • https://lalicorne-hotel.com/userfiles/file/nakazofadorajaz.pdfIn PDF document text
    • http://hasyo.net/files/file/79807259141.pdfIn PDF document text
    • http://land89.com/ckupload/files/92198323811.pdfIn PDF document text
    • http://xn--82cac8d3ajrc0gd0bo4a7nf3qg.com/userfiles/files/zeleroxapolavuteluloganu.pdfIn PDF document text
    • http://alda.pl/ckfinder/userfiles/files/gukuxopewesi.pdfIn PDF document text
    • http://teleinwestor.com/userfiles/file/warapu.pdfIn PDF document text
    • https://petenugilamabo.weebly.com/uploads/1/3/1/4/131453278/f15b508ad9ad.pdfIn PDF document text
    • https://vajdasaraegyesulet.hu/kcfinder/upload/files/nejetatubilesukalozal.pdfIn PDF document text
    • http://legrand-valena.su/kcfinder/upload/files/jeduxebaniwavaloxu.pdfIn PDF document text
    • https://xoxizolijeru.weebly.com/uploads/1/3/0/8/130874154/9e621.pdfIn PDF document text
    • https://youkuvpn.com/upload/files/95060200991.pdfIn PDF document text
    • https://roxracing.eu/userfiles/file/zovavasegogidifut.pdfIn PDF document text
    • http://jobcred.com/rk/jobcred/uploads/image/file/41973982723.pdfIn PDF document text
    • https://stauber.lt/images/files/lugufusejavewugejubenaxe.pdfIn PDF document text
    • https://topas-rus.ru/media-temp/img/uploads/files/solujovetamaretotoruforo.pdfIn PDF document text
    • https://kumazapo.weebly.com/uploads/1/3/2/7/132710765/melupuduliribi.pdfIn PDF document text
    • https://mogopefisumiba.weebly.com/uploads/1/3/5/2/135295831/bf07ca.pdfIn PDF document text
    • https://ozora.schaffsen.com/contents/file/67654414023.pdfIn PDF document text
    • https://apexforestservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/16277bd5c4517d---tedesujibatusiduxa.pdfIn PDF document text
    • https://lebivituwaw.weebly.com/uploads/1/3/1/8/131856954/tegiwepixebi-mutavogune-segezep.pdfIn PDF document text
    • https://garururukipu.weebly.com/uploads/1/3/4/2/134235121/00539e5ef756f7.pdfIn PDF document text
    • http://popmetre.com/news/files/vijebokunil.pdfIn PDF document text
    • https://www.landalastadservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/161fcc4610a59a---49899722910.pdfIn PDF document text
    • http://strandkrabbe-hohenfelde.de/sites/default/files/files/wirasatodajosanewa.pdfIn PDF document text
    • https://reytrans.es/kcfinder/upload/files/gagitazabokopivez.pdfIn PDF document text
    • https://repflex.servermill.com/files/upload/files/nisurujugavuba.pdfIn PDF document text
    • https://nabudurokaralek.weebly.com/uploads/1/3/4/5/134576841/dc29cd46e7d.pdfIn PDF document text
    • https://mofizuzu.weebly.com/uploads/1/3/4/3/134316779/4839708.pdfIn PDF document text
    • https://aydin-elektrik.com/resimler/files/19615108689.pdfIn PDF document text
    • https://akgoz.zemta.com/uploads/files/suvibuvofuvifeves.pdfIn PDF document text
    • https://ehblending.com/wp-content/plugins/super-forms/uploads/php/files/71c1a7e3da7367685b46d35f03473f76/wokevekukigut.pdfIn PDF document text
    • https://bevillelecomte.com/ckfinder/userfiles/files/53162501921.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0003cfe6.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0003cfe6.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0003cfe6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3CFE6 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off0003e7fd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3E7FD 10564 bytes
SHA-256: c2dfaece8337b6ffd4af9d2a116912be7047b462d4b18237de1b8885418a38f3
font_02_sfnt_off0003ffd7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3FFD7 17408 bytes
SHA-256: 4d05a8fad1e36f59c09903600db15efe46cc79387402380efa4845b7337c5117