Malicious PDF — malware analysis report

Static analysis result for SHA-256 875d759ce06cedab…

MALICIOUS

PDF

347.8 KB Created: 2022-03-19 08:10:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-04
MD5: 35bc1b76b7e2451a6ef0879bffcdc7e2 SHA-1: 169d2f3d04a45376ff8e7b422e328a021d0df514 SHA-256: 875d759ce06cedabc674b2d8336d2a1c358328c09182de5a939e340cc51c57e9
166 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.6817

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.sircom.org.br/tools/includes/kcfinder/upload/files/nujuwojafijufolukegut.pdf In PDF document text
    • https://thepetrichortouch.com/wp-content/plugins/super-forms/uploads/php/files/9kb2nc33ddbucigibln2hgabke/basugunumi.pdfIn PDF document text
    • http://dzido.pl/userfiles/file/jaseto.pdfIn PDF document text
    • http://www.scenekunstskolen-efteruddannelsen.dk/ckfinder/userfiles/files/37956317581.pdfIn PDF document text
    • https://renhedc.com/uploads/files/202203160712459690.pdfIn PDF document text
    • http://arquivolta.net/files/10316496650.pdfIn PDF document text
    • https://xylemleads.com/userfiles/file/dawido.pdfIn PDF document text
    • http://znsedu.net/admin/ckeditor/kcfinder/upload/files/23680567411.pdfIn PDF document text
    • https://www.voyagegroupepascher.fr/public/kcfinder/upload/files/jofedida.pdfIn PDF document text
    • http://www.radio-kum.si/data/files/66396045060.pdfIn PDF document text
    • http://mispuntossaga.com/campannas/file/zomelew.pdfIn PDF document text
    • http://unitec-egypt.net/userfiles/file/gutumofipesilirupege.pdfIn PDF document text
    • https://rqconsultores.com/userfiles/file/netidonugegirano.pdfIn PDF document text
    • http://www.alwaysflorida.com/wp-content/plugins/formcraft/file-upload/server/content/files/1621a6ee67a48f---26416530184.pdfIn PDF document text
    • https://sarenpinler.com/calisma2/files/uploads/48767747452.pdfIn PDF document text
    • https://bistro-8.com/wp-content/plugins/super-forms/uploads/php/files/160680e8ec14c149cf2ef476c32b9c51/61340867656.pdfIn PDF document text
    • http://eschool365.in/js/admin/uploadfiles/file/xojisozabisunew.pdfIn PDF document text
    • http://safrano.pl/userfiles/file/38267511123.pdfIn PDF document text
    • http://vijyaiprismcrm.com/userfiles/files/29238166007.pdfIn PDF document text
    • http://christmaslandint.com/userfiles/zesonofejurad.pdfIn PDF document text
    • http://www.fbs-g.com/kcfinder/upload/files/90320392337.pdfIn PDF document text
    • http://anke.de/data/anke.de/uploadfiles/file/pifurasipozozigozotowob.pdfIn PDF document text
    • http://tsetv.kz/app/webroot/js/kcfinder/upload/files/fanusepijegitim.pdfIn PDF document text
    • https://gad-elhak.com/userfiles/file/zikopenisojubopiwasori.pdfIn PDF document text
    • http://ttzco.com/tmp/file/93106344058.pdfIn PDF document text
    • http://humanlitech.com/files/files/dutugawiramulubukadesede.pdfIn PDF document text
    • http://www.krishnashouse.com/ckeditor/kcfinder/upload/files/39061804022.pdfIn PDF document text
    • http://vetcasatenovo.it/userfiles/files/79190124376.pdfIn PDF document text
    • https://reifenscho.de/wp-content/plugins/formcraft/file-upload/server/content/files/1621ccc837750d---rufelejisazazopep.pdfIn PDF document text
    • https://realestatesplatform.com/userfiles/file/86668167515.pdfIn PDF document text
    • http://ophtalmic-overnight.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1620e3deabf575---82437608098.pdfIn PDF document text
    • http://bpsstudio.hu/uploads/61002956275.pdfIn PDF document text
    • http://veganogle.es/uploads/ckfinder/files/ludakumarapusorepikox.pdfIn PDF document text
    • http://aloisiquadri.it/userfiles/files/77074888323.pdfIn PDF document text
    • https://www.baptistenhardenberg.nl/wp-content/plugins/formcraft/file-upload/server/content/files/162353e12878f7---94529119175.pdfIn PDF document text
    • http://vizitcard.kz/uploads/files/57079432475.pdfIn PDF document text
    • https://pomtco.com/technical/files/file/97293841548.pdfIn PDF document text
    • http://okeefesreef.com/ckfinder/userfiles/files/pirogu.pdfIn PDF document text
    • https://fda.weblineinfosoft.com/UserFiles/files/bomibapikipirixipizajep.pdfIn PDF document text
    • https://e-casainteligenta.ro/userfiles/file/wageti.pdfIn PDF document text
    • http://sahrugs.com/userfiles/file/jakevesemusuraj.pdfIn PDF document text
    • http://www.protectakoteasia.com/ckfinder/userfiles/files/zawolidigufajofi.pdfIn PDF document text
    • https://lazav.co.za/XSRYdR1H?utm_term=wow+vanilla+herbalism+guide+1-+300PDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0004fa52.bin)
    +1 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0004fa52.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4FA52 19548 bytes
SHA-256: cbcf2e6f0829060f6442a32b006f37508a245688dfa590aba719108226703f31
font_01_sfnt_off00052d6c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x52D6C 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_02_sfnt_off0005448c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5448C 11360 bytes
SHA-256: 9db2ad1b94545897fcc084ca13888911375d02f74e9eacab22b82bb2379601cd