Malicious PDF — malware analysis report

Static analysis result for SHA-256 89f1934c92355ea1…

MALICIOUS

PDF

89.0 KB Created: 2021-06-10 15:25:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-05-01
MD5: 399cc34e6acc0741dea1f2c33620c404 SHA-1: d5c8d172e06e5f24d672902f29ff91c91082e53f SHA-256: 89f1934c92355ea1768d68caca728fed89e21225b2df4073741ab56c3a80dce0
164 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://oniceh.ru/uplcv?utm_term=meetme+cracked+apk PDF link annotation
    • https://www.groupenahno.com/wp-content/plugins/super-forms/uploads/php/files/uhpf0iaa5rllo2jtmtfjko8t4i/rekejipuraf.pdfIn PDF document text
    • https://holzhaus-suedtirol.it/wp-content/plugins/formcraft/file-upload/server/content/files/16094a54a6d7cd---48624606098.pdfIn PDF document text
    • https://alsterparkett.de/wp-content/plugins/super-forms/uploads/php/files/ge1qi63a1155grirtho95p4att/lukomovekepojoje.pdfIn PDF document text
    • http://bagpack.com.np/wp-content/plugins/formcraft/file-upload/server/content/files/16083ced73f30c---43401601161.pdfIn PDF document text
    • https://www.litesourcenc.com/wp-content/plugins/super-forms/uploads/php/files/d7953ec58294980f25de4f6255594b4c/60930069402.pdfIn PDF document text
    • https://damsindia.org/admin/uploads/file/62469503354.pdfIn PDF document text
    • http://anhuifan.com/upload_fck/file/2021-4-29/20210429233538210208.pdfIn PDF document text
    • http://hiace-yoshikawa.com/js/upload/files/povuxiwonabojijebojanajed.pdfIn PDF document text
    • https://chp-travel.ir/data/file/20987225854.pdfIn PDF document text
    • https://villatoscana-pi.it/userfiles/file/36585077601.pdfIn PDF document text
    • https://agribusiness.pk/wp-content/plugins/formcraft/file-upload/server/content/files/16075f6291b975---wexiguriwa.pdfIn PDF document text
    • https://www.heainc.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bb2518a4e46---8660816584.pdfIn PDF document text
    • http://www.sunaryem.com.tr/wp-content/plugins/super-forms/uploads/php/files/1un66ss93rvccej7dbldflggl3/kegazexuxe.pdfIn PDF document text
    • https://antae.be/app/webroot/uploads/file/faret.pdfIn PDF document text
    • http://www.ascendercorp.com/In extracted file (font_01_sfnt_off0000f507.bin)
    • http://www.ascendercorp.com/typedesigners.htmlIn extracted file (font_01_sfnt_off0000f507.bin)
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn extracted file (font_01_sfnt_off0000f507.bin)
    • http://dejavu.sourceforge.netIn extracted file (font_04_sfnt_off0001404b.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_04_sfnt_off0001404b.bin)

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eab0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEAB0 2900 bytes
SHA-256: ecdac33f38310076e8a3bee5130c29d8b7813210e9f352d9a3d35728ace1cbca
font_01_sfnt_off0000f507.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF507 5076 bytes
SHA-256: 93d299bc3864dce937e4fd9f151061b0f00e9144cec59025df51d7a7d24717f2
font_02_sfnt_off0001063a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1063A 4660 bytes
SHA-256: 445f7edb58106202d595264d156347417f9181ecbf02fe488c89021609b93fdc
font_03_sfnt_off000117f9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x117F9 11972 bytes
SHA-256: 5fbdf8ee6868fd43a0263c5db8d0056477d2061f031e82049efd2d98c70421d4
font_04_sfnt_off0001404b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1404B 16384 bytes
SHA-256: 27d5aa48a66ed6e24074f1b6b97defbd08161f468927a62883f94c9ec160026f