Malicious PDF — malware analysis report

Static analysis result for SHA-256 949ff265ef748943…

MALICIOUS

PDF

432.1 KB Created: 2022-03-10 11:21:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-11
MD5: 4d6a945131b3c604a9129347bdeea739 SHA-1: ee1dd184747289468c2936cc26b01efaf7ca89d4 SHA-256: 949ff265ef7489431c95e299f9c5be5f0ac9a1210c1af1eecccdb32ab2874ec1
114 Risk Score

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4959

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yubit.co.za/XSRYdR1H?utm_term=rachmaninoff+concerto+2+sheet+music PDF link annotation
    • https://rozetki-merten.su/kcfinder/upload/files/megasozeburufa.pdfIn PDF document text
    • https://pajareria.webcordoba.net/kcfinder/upload/files/tupew.pdfIn PDF document text
    • https://fullgame.hu/uploads/files/72326143406.pdfIn PDF document text
    • http://zarya-lugansk.com/userfiles/file/tifodisidonowijemulo.pdfIn PDF document text
    • http://liily.jp/upload/file/20220202211851.pdfIn PDF document text
    • http://artpolinakuzina.ru/pict/file/sufor.pdfIn PDF document text
    • https://jordan.si/dokumenti/file/rusaxemoxoj.pdfIn PDF document text
    • https://alamansyria.com/userfiles/file/burebewi.pdfIn PDF document text
    • https://giraffeng.net/infodaily/gen-ckfinder/userfiles/files/28149420267.pdfIn PDF document text
    • https://webseitenvergleich.com/newerac2c/userfiles/file/duwobevenuwemolomuzoveba.pdfIn PDF document text
    • http://genesisglobalbd.com/assets/ckeditor/kcfinder/upload/files/buzasozitagaver.pdfIn PDF document text
    • http://www.optionassurance.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16200c2b612301---99149750464.pdfIn PDF document text
    • http://gmixlocadora.com.br/admin/kcfinder/upload/files/laxog.pdfIn PDF document text
    • http://engroupe.ca/aym_image/files/wefagewajemo.pdfIn PDF document text
    • http://www.chestheart.org/assets/ckeditor/kcfinder/upload/files/9827679787.pdfIn PDF document text
    • https://lsp.od.ua/wp-content/plugins/super-forms/uploads/php/files/a195435eeb128020412ce57b761e4d77/26069853310.pdfIn PDF document text
    • http://sysquare.com/UserFiles/files/vamiza.pdfIn PDF document text
    • http://usefchina.com/uploadfile/file///2022021212532913.pdfIn PDF document text
    • https://rmp-traueranzeigen.de/cms/files/mulikitobasak.pdfIn PDF document text
    • https://adilakaryakitnakliyat.com/kcfinder/upload/files/19023143758.pdfIn PDF document text
    • http://lycee-elm.org/userfiles/file/razogunipifapefupepik.pdfIn PDF document text
    • https://www.icdsa21.scrs.in/kcfinder/upload/files/60072155960.pdfIn PDF document text
    • http://teppich-bayat.de/kcfinder/upload/files/nenedigefebubaf.pdfIn PDF document text
    • http://www.rodnolespropertymanagement.com/siteuploads/editorimg/file/40762270204.pdfIn PDF document text
    • https://www.synergyom.com/kcfinder/upload/files/64743919886.pdfIn PDF document text
    • http://rund.cz/UserFiles/File/lelowakasekadam.pdfIn PDF document text
    • http://lilipoupoli-drama.gr/lilipoupoli/js/ckfinder/userfiles/files/49625701517.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off00064763.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off00064763.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00064763.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x64763 10820 bytes
SHA-256: 1978685356f22cea022a7a2e5d1988a176686af62ef2885b180d6cc5d2928b56
font_01_sfnt_off00066041.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x66041 21752 bytes
SHA-256: 1d98dbf81c318350d2e2898ef85b100d2a4426ca2419393f7e9ad18e7f306b80
font_02_sfnt_off00069a29.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x69A29 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9