Malicious PDF — malware analysis report

Static analysis result for SHA-256 88bdf472063cc6b5…

MALICIOUS

PDF

306.7 KB Created: 2022-03-07 06:49:28 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-02
MD5: 467205c9e7f7f15f15f4c6dd037fcd9c SHA-1: 85940f39cea382a8da01dfb250a130b6c70e1276 SHA-256: 88bdf472063cc6b578dd6d8c7c9043d8cdab988a4e267b645edfac83db06eaba
221 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.7293

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Travel-support phone-number stuffing scam critical SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF advertises pirated movie streaming/download medium PDF_PIRACY_STREAMING_LURE
    PDF rendered text advertises free full-movie streaming or download using piracy-brand names or a 'full movie + download/free/watch' intent phrase — recovered after folding the styled Unicode confusables the campaign uses to hide those keywords from plain-text detection. These are disposable SEO-spam carriers that route users to malvertising, fake-player, and scam pages; the PDF itself is inert.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://skvely-kup.cz/files/file/13577876869.pdf In PDF document text
    • http://yourhandmadeitems.com/userfiles/file/mugumotexanovovupete.pdfIn PDF document text
    • https://kitapkaplama.com/upload/ckfinder/files/71285716863.pdfIn PDF document text
    • http://rainternacional.com/userfiles/file/dumadisemunimip.pdfIn PDF document text
    • http://loveperfectionschool.com/upload/file/39958412284.pdfIn PDF document text
    • https://www.uralhelicom.com/frontend/web/js/kcfinder/upload/files/memeramabij.pdfIn PDF document text
    • https://massvt.sk/editor_uploads/system/files/31748855953.pdfIn PDF document text
    • http://beiks.info/public/file/6745006987.pdfIn PDF document text
    • http://ivelinabozilova.com/userfiles/file/kopabatuzukim.pdfIn PDF document text
    • https://nocleginaplus.pl/uploads/userfiles/files/13012273028.pdfIn PDF document text
    • http://sentidoseg.com/resources/original/file/52377394573.pdfIn PDF document text
    • https://www.cfo-search.com/wp-content/plugins/formcraft/file-upload/server/content/files/1621eaac997bd7---8124582827.pdfIn PDF document text
    • https://mapst.org/Admin/assets/ckeditor/kcfinder/upload/files/76920990524.pdfIn PDF document text
    • https://fitness-sport.it/userfiles/file/60125974423.pdfIn PDF document text
    • http://spstarekozle.webkoncept.pl/files/file/3617578741.pdfIn PDF document text
    • http://suamayin.biz/userfiles/file/rametafakebu.pdfIn PDF document text
    • http://cmorshomecareassociates.org/uploaded_files/userfiles/files/fuxewemunesozafogaf.pdfIn PDF document text
    • https://vicareyou.com/userfiles/file/19681276499.pdfIn PDF document text
    • http://muzponycompl.muzpony.com/obrazki/file/felafamexupidufip.pdfIn PDF document text
    • https://eirai.org/editor/ckfinder/userfiles/files/37355919368.pdfIn PDF document text
    • http://elai.kz/upload/2022/02files/220218155221828809kwglp.pdfIn PDF document text
    • http://bike-aholic.com/UserFiles/file/70619067632.pdfIn PDF document text
    • https://rubenoferro.com/userfiles/file/gerebisafawep.pdfIn PDF document text
    • https://designmaster.in/scgtest/eec-new/codelibrary/ckeditor/ckfinder/userfiles/files/vadijule.pdfIn PDF document text
    • http://ozdoby-betonowe21.pl/Upload/file/25928878939.pdfIn PDF document text
    • http://www.sosonomo.com/ckfinder/userfiles/files/xidafavasasubodikive.pdfIn PDF document text
    • https://astoraccessories.com/uploads/ckfinder/files/zamodozubomobakivi.pdfIn PDF document text
    • http://www.skupp.pl/wp-content/plugins/formcraft/file-upload/server/content/files/161fc64dab2b4f---pubaximuxepon.pdfIn PDF document text
    • http://studiopignotti.it/userfiles/files/8583699415.pdfIn PDF document text
    • https://hamzakocakoglu.com/userfiles/file/53319721389.pdfIn PDF document text
    • https://aelma.com/sites/default/userfiles/file/2453431394.pdfIn PDF document text
    • http://klavierunterricht-bergedorf.de/files/files/gofom.pdfIn PDF document text
    • https://jurvamartin.com/userfiles/file/96850620753.pdfIn PDF document text
    • https://lemondedelaura.com/userfiles/file/wizagiwabaj.pdfIn PDF document text
    • https://www.camaragranada.org/administracion/kcfinder/upload/files/tagixelukig.pdfIn PDF document text
    • http://........��In PDF document text
    • https://colod.co.za/XSRYdR1H?utm_term=stream+video+from+google+drive+android+studioPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off00045448.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off00045448.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00045448.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x45448 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_01_sfnt_off00046b68.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x46B68 10940 bytes
SHA-256: 7aaf7b0c3623f9e11357229bc530f7b9f3e4bdf92b9be342d1a754cb20eef251
font_02_sfnt_off0004848b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4848B 20384 bytes
SHA-256: 1d14cd335ff168c7d60b376ba58224db3ea7a97df1ecc6717c2a886c02b75323