Malicious PDF — malware analysis report

Static analysis result for SHA-256 a9cd1fb1a777feb6…

MALICIOUS

PDF

77.7 KB Created: 2022-04-12 20:43:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-27
MD5: 6f1327983490a6b1e7ad483e0b6af98f SHA-1: 81c810468b10688d2554c2582c9ca3632e68df87 SHA-256: a9cd1fb1a777feb63865f42893de0201195c8196b31850855fc96b4774fecd89
186 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lazav.co.za/YmrXLWy8?keyword=brother%20knitting%20machine%20model%20kh-800 PDF link annotation
    • http://pn-tech.net/userData/board/file/pisata.pdfIn PDF document text
    • http://xn----ftbkdcamitb5h.xn--p1acf/files/fck/file/99598607691.pdfIn PDF document text
    • https://netulomite.weebly.com/uploads/1/3/2/8/132814473/gosamu.pdfIn PDF document text
    • https://aviatroglo.fr/IMG/file/fadupisaku.pdfIn PDF document text
    • https://www.frontiermyanmar.com/sites/all/libraries/ckfinder/userfiles/files/59778825530.pdfIn PDF document text
    • https://deluneruniji.weebly.com/uploads/1/3/4/0/134012649/wemuwiju.pdfIn PDF document text
    • https://favunabev.weebly.com/uploads/1/3/4/4/134445728/kimovabuwaliv-xisulanamejat-tajusubimejefa.pdfIn PDF document text
    • https://tipuzivi.weebly.com/uploads/1/3/0/9/130969377/853c5d.pdfIn PDF document text
    • https://gpuhub.net/wp-content/plugins/super-forms/uploads/php/files/3lvr05aeh2flmefpshq6cqipnf/nekuravozobalodis.pdfIn PDF document text
    • https://pafirovax.weebly.com/uploads/1/3/4/6/134662293/832ef1539f04.pdfIn PDF document text
    • https://fozabenuguze.weebly.com/uploads/1/3/4/6/134685739/6908273.pdfIn PDF document text
    • https://magiccat.pro/ckfinder/userfiles/files/tofesozexuxefuragomapakev.pdfIn PDF document text
    • https://sazinuje.weebly.com/uploads/1/3/4/5/134588850/jopoxejitizefuxobif.pdfIn PDF document text
    • http://cainghienbinhduong.com/uploads/userfiles/file/69384977514.pdfIn PDF document text
    • https://sevokubataper.weebly.com/uploads/1/3/0/8/130814346/958984.pdfIn PDF document text
    • http://police8coop.com/UserFiles/file/24785481327.pdfIn PDF document text
    • https://wodokapiv.weebly.com/uploads/1/3/4/5/134584818/627f1c5374d.pdfIn PDF document text
    • https://gebigimudixerez.weebly.com/uploads/1/3/4/3/134374499/5388042.pdfIn PDF document text
    • http://protech.com.ng/wp-content/plugins/formcraft/file-upload/server/content/files/162418651f0c13---63676052863.pdfIn PDF document text
    • http://www.sloepverhuur-debiesbosch.nl/upload/files/felumivitejomoredef.pdfIn PDF document text
    • http://stickers-moins-cher.com/userfiles/stickers-moins-cher.com/file/matorumorajuboxozezomiseb.pdfIn PDF document text
    • https://baxodibidixajit.weebly.com/uploads/1/3/5/3/135311382/dakesijazuvit_pelavafupezod_xikas_sikexezobi.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0000c853.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0000c853.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c853.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC853 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off0000e06a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE06A 11160 bytes
SHA-256: 84ebd0fd93e6ff719ae65f94d8ca00533b2522f382f939feb6fd2e1f4ffadf86
font_02_sfnt_off0000fa2b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFA2B 16956 bytes
SHA-256: e7a3b2b161351ac8bf7fd2ae22ea6c66e2cafe3bb5ee4df3b41eeb4a8723a41a