Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca61888f27627c2f…

MALICIOUS

PDF

264.2 KB Created: 2022-04-23 07:35:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-07
MD5: 6553297ece3b8f3e9623f708700fda76 SHA-1: e16b9077bbcbf25e7d0d2ccaa714f1da891fe5e4 SHA-256: ca61888f27627c2faa6f77f04f52aa71797a46d0522ca5cf7b39e76ca2c2391d
172 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.7466

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Travel-support phone-number stuffing scam critical SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • SEO-redirector lure link (multi-word utm_term) low PDF_SEO_UTM_REDIRECTOR_LINK
    PDF contains a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the search-keyword gateway used by the 'free document download' phishing family. Surfaced as an IOC; on its own this is a low-confidence signal.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://tevav.co.za/XSRYdR1H?utm_term=play+store++pending+problem+solved PDF link annotation
    • https://deycaterers.com/ckfinder/userfiles/files/mofozumukijo.pdfIn PDF document text
    • http://mamtaniketan.com/userfiles/file/18212047790.pdfIn PDF document text
    • https://albertsdrukwerk.nl/bestanden/files/bodibijatibiw.pdfIn PDF document text
    • https://vigisamale.weebly.com/uploads/1/4/1/4/141411172/ruvatok.pdfIn PDF document text
    • https://gamiwejejorar.weebly.com/uploads/1/3/4/4/134498461/gusireduwiz_voxit.pdfIn PDF document text
    • https://pepazosek.weebly.com/uploads/1/3/4/1/134108786/ff0ce3c0a361.pdfIn PDF document text
    • https://www.rapn.ru/ckfinder/userfiles/files/62697528918.pdfIn PDF document text
    • http://pro-customer.de/userfiles/file/mufavelagisizodajop.pdfIn PDF document text
    • https://rawutakoze.weebly.com/uploads/1/3/4/3/134326806/adf9ab93.pdfIn PDF document text
    • https://fetepidema.weebly.com/uploads/1/3/4/6/134684810/354971d.pdfIn PDF document text
    • https://gigiwejube.weebly.com/uploads/1/3/5/9/135984489/riwuxerifise.pdfIn PDF document text
    • http://clubsahdianagalati.ro/upload/editor/file/32410376124.pdfIn PDF document text
    • https://devopududifuwet.weebly.com/uploads/1/3/2/6/132696325/0931f2.pdfIn PDF document text
    • http://4998horo.gmmwireless.com/contents/files/vuguvodunopijewip.pdfIn PDF document text
    • https://kitewozobubipu.weebly.com/uploads/1/3/4/5/134527197/roxenone.pdfIn PDF document text
    • https://dakhoathienan.com/users/files/20562225586.pdfIn PDF document text
    • https://karupijelajedo.weebly.com/uploads/1/3/4/8/134878973/nivinojofo-sakanidalov-gugavogawila.pdfIn PDF document text
    • https://nebumokijisuj.weebly.com/uploads/1/3/5/3/135326708/80124eeae25b4.pdfIn PDF document text
    • https://vagibize.weebly.com/uploads/1/3/4/6/134618654/11393043.pdfIn PDF document text
    • https://dewebunofimob.weebly.com/uploads/1/3/3/9/133986907/5244801.pdfIn PDF document text
    • http://xn--12ca5eb0atfbad4eh5ai1ef5bg6a8png.com/UserFiles/file/gawagafo.pdfIn PDF document text
    • http://sinkrontech.hu/admin/kcfinder/upload/files/bupufikofapivezewijofepa.pdfIn PDF document text
    • https://bevabuje.weebly.com/uploads/1/3/4/8/134897483/483ecce9e.pdfIn PDF document text
    • https://kijojodifufu.weebly.com/uploads/1/3/4/3/134317180/bikiwikuriz.pdfIn PDF document text
    • https://toxozuduz.weebly.com/uploads/1/3/5/2/135295771/rarogowuxesakev_jirivavuda_suzavo_nidufutivekivam.pdfIn PDF document text
    • https://wovusowi.weebly.com/uploads/1/3/4/8/134886666/wunigigabobajogi.pdfIn PDF document text
    • https://kamwalibais.com/userfiles/file/25403221814.pdfIn PDF document text
    • https://www.agro-zavod.ru/app/webroot/js/ckfinder/userfiles/files/96540935484.pdfIn PDF document text
    • https://devoligoj.weebly.com/uploads/1/3/7/5/137509872/jisirin.pdfIn PDF document text
    • https://wejibuxod.weebly.com/uploads/1/3/0/7/130740202/rinufobegut.pdfIn PDF document text
    • http://xperion.hu/wp-content/plugins/super-forms/uploads/php/files/b35025b8e10ed51a92dd4e25ef836ec4/41328466400.pdfIn PDF document text
    • https://nolelagisumo.weebly.com/uploads/1/3/4/1/134132353/c767ed7c06cc.pdfIn PDF document text
    • https://towavakivuno.weebly.com/uploads/1/3/5/3/135318123/12348.pdfIn PDF document text
    • http://smartpaintingplus.com/userfiles/files/kovakotefotuxuk.pdfIn PDF document text
    • https://famotufenimuz.weebly.com/uploads/1/3/4/1/134132127/7899844.pdfIn PDF document text
    • https://buronoveze.weebly.com/uploads/1/3/0/7/130739674/bumafexudiwal_bujufamifitulat_libitami.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0003ac45.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0003ac45.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0003ac45.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3AC45 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off0003c457.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3C457 19828 bytes
SHA-256: c41d5a4ce37dd939cb1208e52200c9ee5a22f4c658f2c6854e4ff1fd43c95702
font_02_sfnt_off0003f7a8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3F7A8 11056 bytes
SHA-256: 37291e3100c66a27a8b77ebac6fb9827dad183edcda584c5a1b4a492095bc8b9