Malicious PDF — malware analysis report

Static analysis result for SHA-256 847f50297739b694…

MALICIOUS

PDF

261.0 KB Created: 2022-02-07 05:13:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-05
MD5: 5b1da71989d8dcefa96662cf4f0a5f48 SHA-1: d6a14ba25e7c08627d467b3c7cc40435442f0850 SHA-256: 847f50297739b694c37ace05ca6e4635c67840ae10b85a35415b076d085b7a7d
166 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.5678

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://norin.co.za/XSRYdR1H?utm_term=dime+3d+video+player+apk PDF link annotation
    • http://kleni.cz/userfiles/file/97151619370.pdfIn PDF document text
    • http://zonwering-belgie.eu/ckfinder/userfiles/files/fepasegoxizoxuzakulebudo.pdfIn PDF document text
    • https://baconbites.com/wp-content/plugins/super-forms/uploads/php/files/s5mvrvjvrbg6e9fajnjbcpbb31/pasemu.pdfIn PDF document text
    • http://shannonlakeestates.org/fck_images/file/30309552323.pdfIn PDF document text
    • http://www.sunarsurdurulebilir.com/wp-content/plugins/super-forms/uploads/php/files/08jpjpeddnhtfcb712pkcniqd7/wasezabukadufomeleweza.pdfIn PDF document text
    • https://irish-setter-zucht.info/ckfinder/userfiles/files/winuvupe.pdfIn PDF document text
    • https://maria-galland.ru/files/file/vebuwowarix.pdfIn PDF document text
    • http://cokhihoaiduc.com/uploads/files/namogumotunamebigiz.pdfIn PDF document text
    • http://pololanna.com/user_img/files/nixadogaligopogafaginija.pdfIn PDF document text
    • http://proreferee.ru/uploads/ckfinder/files/belibomavelenabupenazopi.pdfIn PDF document text
    • https://marosme.ro/hirek/file/8062858182.pdfIn PDF document text
    • https://nsaimmigration.com/userfiles/file/6606963955.pdfIn PDF document text
    • http://kartonpier.com/admin/kcfinder/upload/files/12392229170.pdfIn PDF document text
    • https://arabadvertise.com/tempimg/file/43931582497.pdfIn PDF document text
    • http://eachfun.com/ckfinder/userfiles/site_eachfun_com/files/jaxufubugisutefenodo.pdfIn PDF document text
    • https://www.nobleorthodontic.com/wp-content/plugins/super-forms/uploads/php/files/40b8d4564df92bce123db88fc80db4f5/99339508018.pdfIn PDF document text
    • http://windowsplusllc.com/ckfinder/userfiles/files/bobixozu.pdfIn PDF document text
    • http://www.nationaalgolfcongres.nl/wp-content/plugins/formcraft/file-upload/server/content/files/161405f3f3f2b8---budafatuwetujeru.pdfIn PDF document text
    • http://stopasbestos.ca/wp-content/plugins/formcraft/file-upload/server/content/files/161a494f6d8233---11758142255.pdfIn PDF document text
    • https://total-sport.pl/img/upload/files/natovaxona.pdfIn PDF document text
    • https://slavica.ru/wp-content/plugins/super-forms/uploads/php/files/084bff09613c503eef497f0b813b09b4/5539411082.pdfIn PDF document text
    • https://ewastexperts.com/userfiles/files/sopemuvuvawakikepesiji.pdfIn PDF document text
    • http://www.salda.se/saldus/kcfinder/upload/files/81667050315.pdfIn PDF document text
    • https://holocaustresearch.pl/nowy/photo/file/10721659221.pdfIn PDF document text
    • https://parklanehotel.asia/userfiles/file/68846003970.pdfIn PDF document text
    • http://m-s-g.ru/userfiles/files/jowevoraganexo.pdfIn PDF document text
    • https://wojczak.pl/userfiles/file/58802822563.pdfIn PDF document text
    • https://nikolsbeauty.com/webroot/f/uploads/file/totubi.pdfIn PDF document text
    • http://hakanhurdacilik.com/userfiles/file/78870004564.pdfIn PDF document text
    • http://exmar.it/foto_fck/file/nowafomosil.pdfIn PDF document text
    • http://influences-vegetales.eu/assets/Image//files/zuvesujowibepebiwo.pdfIn PDF document text
    • https://www.tailormadeholidayspt.com/kcfinder/upload/files/36309337667.pdfIn PDF document text
    • http://ebsenglish.net/_UploadFile/Images/file/xevoruxufovu.pdfIn PDF document text
    • http://gtlitalia.com/userfiles/files/kofazadafatubigafafori.pdfIn PDF document text
    • https://estidevelopers.com/wp-content/plugins/super-forms/uploads/php/files/3e21dbb37f697aede87495d34706e6c9/nowubusoderokebegej.pdfIn PDF document text
    • http://kronospan-mofa.hu/editor_up/23919362033.pdfIn PDF document text
    • http://bright-inter.com/file_media/file_image/file/papizinulow.pdfIn PDF document text
    • http://ednak.com/wp-content/plugins/formcraft/file-upload/server/content/files/1617b8a880e15c---rediwomozibajubeferegi.pdfIn PDF document text
    • http://strap.sk/uploads/file/vafujefakapopufim.pdfIn PDF document text
    • http://ebslang.net/_UploadFile/Images/file/denakofa.pdfIn PDF document text
    • http://uralinteh.com/uploads/files/80853107424.pdfIn PDF document text
    • https://webbsoil.com/home/webb/public_html/ckfinder/userfiles/files/worebijiped.pdfIn PDF document text
    • http://wingmanplanningdemo.com/userfiles/files/74942405058.pdfIn PDF document text
    • http://dragoniresorts.com/userfiles/46581649597.pdfIn PDF document text
    • http://merten-antik.su/kcfinder/upload/files/72996345409.pdfIn PDF document text
    • https://ntc-container.com/upload/files/jabanokinoruzaxisud.pdfIn PDF document text
    • https://blsautomation.com/ckfinder/userfiles/files/gekulaxesusubog.pdfIn PDF document text
    • https://rizecanreklam.com/images/file/9277667715.pdfIn PDF document text
    • https://shrmivirtual.org/wp-content/plugins/super-forms/uploads/php/files/7f4161daf85b0eaf90d22d8305e71319/20011891884.pdfIn PDF document text
    +9 more URL(s)

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0003846b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3846B 5388 bytes
SHA-256: 047e56e6700ee4300de4613b613acc26f49b9fddca2db3f6d0122049957ee8c4
font_01_sfnt_off0003978d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3978D 24424 bytes
SHA-256: 04dcfa6d3016ac5969ee3889101a45c0facb48529d174fd743f4dea6ce7df5c2
font_02_sfnt_off0003d40b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3D40B 10628 bytes
SHA-256: 9de88152e26a4874d9c9f7b5464789bec501db2d72036985f779ccf6ea6a36f0
font_03_sfnt_off0003ec6f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3EC6F 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9