Malicious PDF — malware analysis report

Static analysis result for SHA-256 d64bc8a595bf69ce…

MALICIOUS

PDF

220.6 KB Created: 2022-04-30 02:16:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-04-25
MD5: c7d7571f002a5b24d957eb676c46d14d SHA-1: bafa38b5e599a72bfcf201cbc9cbdb76de8bcdbc SHA-256: d64bc8a595bf69ce35cab429df92f601372d917c66b6fb51de365ff6049a8d51
136 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9575

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://sunuf.co.za/XSRYdR1H?utm_term=basalt+rock+fibre+journals.+pdf PDF link annotation
    • https://sezunugavekavo.weebly.com/uploads/1/3/5/3/135321765/3085d1.pdfIn PDF document text
    • https://fuzobiwi.weebly.com/uploads/1/3/4/7/134717163/1185891.pdfIn PDF document text
    • http://mayfairplace50.com/kcfinder/upload/files/wetajifudoriba.pdfIn PDF document text
    • https://kermoulin.com/userfiles/file/kibog.pdfIn PDF document text
    • http://futurepoolspa.com/ckfinder/userfiles/files/wadiwuxava.pdfIn PDF document text
    • http://blue-balloon.pl/files/files/61139557791.pdfIn PDF document text
    • http://xn--b1agjlwjc3g.xn--p1ai/ckfinder/userfiles/files/86436270825.pdfIn PDF document text
    • https://kuvakikarubefi.weebly.com/uploads/1/3/1/3/131383404/gabezerumafugub.pdfIn PDF document text
    • https://delosixopefo.weebly.com/uploads/1/3/4/3/134344482/jusebetasujekijik.pdfIn PDF document text
    • https://exam12.menapoint.com/app/webroot/upload/files/21010203090.pdfIn PDF document text
    • http://cpbnatation.fr/fckeditor/userfiles/file/nodokigidunig.pdfIn PDF document text
    • http://skup-laptopow.com/wp-content/plugins/formcraft/file-upload/server/content/files/162400a9974db9---37918522329.pdfIn PDF document text
    • https://alkalacarservice.com/public_html/userfiles/file/kizov.pdfIn PDF document text
    • https://daxivikulogator.weebly.com/uploads/1/3/4/3/134308382/webirupofolegiz.pdfIn PDF document text
    • http://abaj.cz/UserFiles/File/8978332969.pdfIn PDF document text
    • https://vikta-fish.ru/upload/files/busexumatakadamokop.pdfIn PDF document text
    • http://main-target.com/userfiles/files/3257589039.pdfIn PDF document text
    • https://it-remarketing.pl/app/webroot/media/files/kejagenubawawotepalu.pdfIn PDF document text
    • https://wazalopa.weebly.com/uploads/1/3/0/8/130814586/vusojoxav_gepig_janukalijavo.pdfIn PDF document text
    • https://dibexawalezi.weebly.com/uploads/1/3/4/7/134760597/bapukasurabar.pdfIn PDF document text
    • http://onelove.cz/file/jinodazaf.pdfIn PDF document text
    • http://sovaimm.it/userfiles/files/futuwupen.pdfIn PDF document text
    • https://bojepelesu.weebly.com/uploads/1/3/5/3/135350442/6639942.pdfIn PDF document text
    • http://mustafaulusoy.com/dosyalar/File/peserufiwivufenumike.pdfIn PDF document text
    • https://mujamixoto.weebly.com/uploads/1/3/0/7/130776872/wojowefowe.pdfIn PDF document text
    • https://pmayassam.in/assets/kcfinder/upload/files/wonuboweribirapebotewoku.pdfIn PDF document text
    • http://cpk.by/ckfinder/userfiles/files/mesep.pdfIn PDF document text
    • https://alusol-kw.com/ckfinder/userfiles/files/45626769319.pdfIn PDF document text
    • http://mustang.tom.ru/jsplugins/ckfinder/userfiles/files/77098829798.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0002fa94.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0002fa94.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002fa94.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2FA94 11192 bytes
SHA-256: ae0386bb5454ad9e2490ecbb63193db385c9f7ef3dac4ffa59ff08bc46bda48d
font_01_sfnt_off000314b3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x314B3 21280 bytes
SHA-256: 78e69f6bfef018098bae045bf143952368c1df2d50be066e39d6e72b024758ca
font_02_sfnt_off00034c00.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x34C00 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1