Malicious PDF — malware analysis report

Static analysis result for SHA-256 875e6ea4c5f857d7…

MALICIOUS

PDF

341.9 KB Created: 2022-01-30 05:57:30 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-05
MD5: 66bb253caa6e49c4470cea12ff120df8 SHA-1: ecc57675e53e2923b91d0c14b78388c8d6350b0a SHA-256: 875e6ea4c5f857d7485d4a569d9d8c5a4925c047c89c46920169d632ba352a9d
191 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.6543

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • PDF advertises pirated movie streaming/download medium PDF_PIRACY_STREAMING_LURE
    PDF rendered text advertises free full-movie streaming or download using piracy-brand names or a 'full movie + download/free/watch' intent phrase — recovered after folding the styled Unicode confusables the campaign uses to hide those keywords from plain-text detection. These are disposable SEO-spam carriers that route users to malvertising, fake-player, and scam pages; the PDF itself is inert.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yoyep.co.za/XSRYdR1H?utm_term=video+from+vimeo+to+mp4 PDF link annotation
    • https://amrapalispot.com/userfiles/file/fogadepapalida.pdfIn PDF document text
    • https://oreopay57.com/ckfinder/userfiles/files/xonaduninevisebivowovewa.pdfIn PDF document text
    • http://mh-gartengestaltung.de/userfiles/file/24456508133.pdfIn PDF document text
    • https://foodthings.us/userfiles/file/fukuveja.pdfIn PDF document text
    • http://smalternatywa.pl/media/upload/files/a7a5051af155a9b39ccf340d7b77a273.pdfIn PDF document text
    • http://vinhthuan.com/upload/files/95859506620.pdfIn PDF document text
    • http://sunway.me/uploads/file/110535362520.pdfIn PDF document text
    • https://fitnessrev.net/wp-content/plugins/super-forms/uploads/php/files/e2dieq0lvbq1f8efa4sk9p6beq/13664354008.pdfIn PDF document text
    • http://kawana.tech/userfiles/file/20264328944.pdfIn PDF document text
    • http://fohow77.ru/upload/file/kojodubewoxeletonilabe.pdfIn PDF document text
    • https://www.bosingels.nl/ckfinder/userfiles/files/xisinavanorawuxafapi.pdfIn PDF document text
    • http://shendaoguoji.com/data/attachment/file/95827585676.pdfIn PDF document text
    • http://df-foundry.net/d/files/2693079240.pdfIn PDF document text
    • https://gyogytorna-vac.hu/admin/kcfinder/upload/files/16674958245.pdfIn PDF document text
    • http://7seapharmtech.com/Uploadfiles/files/denenifixakiz.pdfIn PDF document text
    • http://longarmquiltacademy.net/fckeditor/userfiles/file/35617226988.pdfIn PDF document text
    • http://balashixa.inhome360.ru/admin/ckfinder/userfiles/files/sopixukiti.pdfIn PDF document text
    • https://nusbetaja2.com/contents/files/8232362609.pdfIn PDF document text
    • https://www.ibericaseguridad.com/admin/kcfinder/upload/files/viziw.pdfIn PDF document text
    • https://massagetheory.ca/wp-content/plugins/super-forms/uploads/php/files/a60075481096ea959dc9bd10364908bf/lubokin.pdfIn PDF document text
    • http://vinhomeshaiphong.net/app/webroot/img/files/34933608215.pdfIn PDF document text
    • https://noble-worldwide.com/wp-content/plugins/super-forms/uploads/php/files/06afb43e0cfbbb17f6ace2272068488d/medimufufamag.pdfIn PDF document text
    • http://billedbutikken.dk/articlefiles/file/fipukodufilebufedo.pdfIn PDF document text
    • http://girls-club.jp/app/webroot/js/kcfinder/upload/files/ronixin.pdfIn PDF document text
    • http://rexant.by/upload/editor/files/jotajivan.pdfIn PDF document text
    • http://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/16177821f40ec2---77034978239.pdfIn PDF document text
    • http://yuanjen.com/ckfinder/userfiles/files/nitosufuvusawabowetipo.pdfIn PDF document text
    • http://eminenceinc.com/userfiles/file/41707716561.pdfIn PDF document text
    • https://lederstuhlshop.de/ckfinder/userfiles/files/31178747771.pdfIn PDF document text
    • https://jamuiboe.com/webroot/upload_media/1947027985.pdfIn PDF document text
    • http://urbancollab.com/userfiles/Proj_Name/files/riwobetemaz.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0004ec1b.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0004ec1b.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0004ec1b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4EC1B 18076 bytes
SHA-256: a82d1bbeb9b808a47cc08c6df4b6d725920c521cffae67e82278adbadb9e8710
font_01_sfnt_off00051a10.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x51A10 16416 bytes
SHA-256: cfa2c3fbce80cc5607e01af033b793d17c57c214fb1d96e845eedea48cccd336
font_02_sfnt_off000530b4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x530B4 10292 bytes
SHA-256: fbe743b2fc31bf1e06649c167e60227fcc972d332d11fa9ab742ddde0391168f