Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7da8394b3930999…

MALICIOUS

PDF

76.8 KB Created: 2022-04-02 23:53:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-28
MD5: d5350dd8ffb63abeb9be5894f13727ad SHA-1: 02a02b6ea24f4964c23a3d08f2a44421ee3bebda SHA-256: c7da8394b39309997023d85f2e8573f2016f348c1af2475f820f27e85ddc1f52
186 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://puxalumanog.weebly.com/uploads/1/3/4/6/134648941/lajizokon.pdf In PDF document text
    • https://domexuvuk.weebly.com/uploads/1/3/0/7/130740212/vufakefuvulak.pdfIn PDF document text
    • https://wojasatog.weebly.com/uploads/1/3/4/7/134765175/segifokojenubumitow.pdfIn PDF document text
    • https://lazesomixasima.weebly.com/uploads/1/3/4/5/134588612/5950945.pdfIn PDF document text
    • https://at2-turbo-j3t.com/contents/files/ruzujevedumil.pdfIn PDF document text
    • https://kopojari.weebly.com/uploads/1/3/4/5/134585935/vitoz.pdfIn PDF document text
    • https://navikeput.weebly.com/uploads/1/3/4/7/134755574/pafikotizazipasato.pdfIn PDF document text
    • https://kudumegowejo.weebly.com/uploads/1/3/4/2/134266354/towabuxofudu.pdfIn PDF document text
    • https://jipunusib.weebly.com/uploads/1/3/0/8/130813609/laxipofu_jutizexapapel.pdfIn PDF document text
    • http://www.tractortools.cz/ckfinder/userfiles/files/vijaropaxipobofubojevizek.pdfIn PDF document text
    • https://www.alertgy.com/wp-content/plugins/super-forms/uploads/php/files/59fb0e3468d2f414e9ff6a379114d191/sivofukuru.pdfIn PDF document text
    • https://jupikojeba.weebly.com/uploads/1/3/0/9/130968920/8484039.pdfIn PDF document text
    • https://kabaposirivapej.weebly.com/uploads/1/3/2/6/132680813/ea5cc3c30aac5.pdfIn PDF document text
    • https://zokemubolito.weebly.com/uploads/1/3/4/8/134895641/javuzowovel.pdfIn PDF document text
    • https://fotinodonana.weebly.com/uploads/1/3/4/6/134692009/e3d393c3c046.pdfIn PDF document text
    • https://gesajapuso.weebly.com/uploads/1/3/4/8/134873290/8795523.pdfIn PDF document text
    • https://kipamafulu.weebly.com/uploads/1/3/4/5/134588126/bafasi.pdfIn PDF document text
    • https://bowefolezoz.weebly.com/uploads/1/3/1/4/131407704/936925.pdfIn PDF document text
    • https://repepojopojak.weebly.com/uploads/1/3/5/9/135970902/e7265dab.pdfIn PDF document text
    • https://kekuxepepave.weebly.com/uploads/1/3/0/7/130739312/fasudogo.pdfIn PDF document text
    • https://fekujerixotose.weebly.com/uploads/1/3/4/8/134896765/jinili.pdfIn PDF document text
    • https://sunuf.co.za/YmrXLWy8?keyword=how%20to%20replace%20carrier%20blower%20motorPDF link annotation
    • https://jonilokakowoso.weebly.com/uploads/1/3/1/4/131453896/muxuxapi_zezan_ritogijenuw.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0000cad3.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0000cad3.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cad3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCAD3 10480 bytes
SHA-256: 0bc7fd63272a589f3a9d8cc4144f08870544cd9c729077315c9ab0c890a6e297
font_01_sfnt_off0000e26a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE26A 16528 bytes
SHA-256: 9813834efa60468e6d22688db3e81be32ce77d9474885b2700821a7165040abe
font_02_sfnt_off00010d4a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10D4A 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1