Malicious PDF — malware analysis report

Static analysis result for SHA-256 ddd6099237701cd6…

MALICIOUS

PDF

346.3 KB Created: 2022-02-01 22:49:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-07-16
MD5: 160549c5509fd6b09f2d4a0f8691e989 SHA-1: 6eb3cbd9a55cb1d5520e17be96480ba02fbf3722 SHA-256: ddd6099237701cd6cc514370f85fc0ac9a11e98bb38723a4c53dd9978904c976
191 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.5320

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • PDF advertises pirated movie streaming/download medium PDF_PIRACY_STREAMING_LURE
    PDF rendered text advertises free full-movie streaming or download using piracy-brand names or a 'full movie + download/free/watch' intent phrase — recovered after folding the styled Unicode confusables the campaign uses to hide those keywords from plain-text detection. These are disposable SEO-spam carriers that route users to malvertising, fake-player, and scam pages; the PDF itself is inert.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mifuj.co.za/XSRYdR1H?utm_term=mobogenie+market+for+pc+free PDF link annotation
    • https://mancomunidadvaldizarbe.com/userfiles/files/78964748592.pdfIn PDF document text
    • http://aimecostruzioni.it/userfiles/files/52358181415.pdfIn PDF document text
    • http://goldmustang.com/files/files/gagiburikipogafapotamubu.pdfIn PDF document text
    • http://tubesealer.com/uploaded/file/1496838499616b4f3278d0a.pdfIn PDF document text
    • http://mofald-clpiu.gov.np/public/kcfinder/upload/files/15132521464.pdfIn PDF document text
    • http://ecoaga.com/documentos/file/9494712070.pdfIn PDF document text
    • http://polipack.ru/content/file/59559101269.pdfIn PDF document text
    • https://ccskin.com/geektic/files/kerobegafevizo.pdfIn PDF document text
    • https://stradatextiles.com/upload/ckfinder/files/18420956978.pdfIn PDF document text
    • http://aktivnistari.eu/uploads/files/fazikapozimorifokab.pdfIn PDF document text
    • http://www.sunarsurdurulebilir.com/wp-content/plugins/super-forms/uploads/php/files/sdftq2q5eo352v731t0ohne9o7/vedudamekakixoteveke.pdfIn PDF document text
    • https://zemiigori.com/uploads/file/3149537522.pdfIn PDF document text
    • https://doxity.ro/ckfinder/userfiles/files/zavijixikuf.pdfIn PDF document text
    • http://thumuavechai.com/vietkiendo/upload/file/55717923697.pdfIn PDF document text
    • http://foto-klub.dk/userfiles/file/fawatidijokoxuvolop.pdfIn PDF document text
    • https://stmpallet.com/ckfinder/userfiles/files/mowivixujavewa.pdfIn PDF document text
    • http://reclaimsplus.com/wp-content/plugins/super-forms/uploads/php/files/50a06551b4f8ba2ede8e5eb07e1f0ca0/12870585548.pdfIn PDF document text
    • https://chuyennhakienvangvn.net/upload/files/92794084615.pdfIn PDF document text
    • http://dymenahealthcare.com/upload/fckeditor/file/90390703559.pdfIn PDF document text
    • http://finproekt-msk.ru/userfiles/file/13811989226.pdfIn PDF document text
    • https://drisraadentalcenter.com/userfiles/file/dazafifurivubodel.pdfIn PDF document text
    • http://www.miamiairportlimo.net/wp-content/plugins/formcraft/file-upload/server/content/files/160df867c044ce---84479118950.pdfIn PDF document text
    • https://www.amata.org.uk/ckfinder/userfiles/files/verowiwupamasewapomunak.pdfIn PDF document text
    • http://ei-windykacja.pl/upload/file/ronapeguta.pdfIn PDF document text
    • http://veedik.net/assets/admin/kcfinder/upload/files/gebezefusugonujejiren.pdfIn PDF document text
    • https://medicentrumnz.eu/medicentrum/files/file/xubukususasuduxodivaka.pdfIn PDF document text
    • https://atlastoursntravels.com/userfiles/file/jojuzekigudero.pdfIn PDF document text
    • https://gosselindesign.com/images/from_fckeditor/fichiers/79521931391.pdfIn PDF document text
    • https://pasationtravellers.com/root/FCKeditor/file/54796785915.pdfIn PDF document text
    • https://www.mnogotrop.com/ckfinder/userfiles/files/14390465481.pdfIn PDF document text
    • http://elskup.stycznik.eu/images/assets/file/jupawitugebabiguxum.pdfIn PDF document text
    • http://fulepmark.hu/nyebu/fulepmark/userfiles/file/vesug.pdfIn PDF document text
    • http://lmleadmanagement.com/userfiles/files/59186419413.pdfIn PDF document text
    • https://adminshantitechnical.com/userfiles/file/38719544382.pdfIn PDF document text
    • http://richmore.kr/uploadfile/fckeditor/file/39519156281.pdfIn PDF document text
    • http://pawsandtiaras.com/ckfinder/userfiles/files/zejelabi.pdfIn PDF document text
    • http://elpijisystem.com/file/farixorisevuresu.pdfIn PDF document text
    • http://xn----8sbnbd9chja.xn--p1ai/userfiles/file/25089624537.pdfIn PDF document text
    • https://creationstationdance.com/wp-content/plugins/formcraft/file-upload/server/content/files/161eb92af2539f---1212335149.pdfIn PDF document text
    • http://kirpichi.su/kcfinder/upload/files/sikovalefarexogowepeni.pdfIn PDF document text
    • https://www.unicodesystems.com/wp-content/plugins/super-forms/uploads/php/files/jp1i884e1872oq1ga6875fmmp4/99710607983.pdfIn PDF document text
    • http://korio-olsztyn.pl/userfiles/file/faxumodomorafom.pdfIn PDF document text
    • https://sonarmusic.hu/up_image/file/32328641176.pdfIn PDF document text
    • https://www.davidcosz.de/wp-content/plugins/super-forms/uploads/php/files/hfjikbqgvi5h30188oimgjvo9r/98039895593.pdfIn PDF document text
    • http://studiosiriosrl.it/userfiles/files/zekinogajuvimirotazegojiv.pdfIn PDF document text
    • http://www.derbysignandgraphics.com/uploads/file/bafezilotaribakib.pdfIn PDF document text
    • http://www.sun-green.eu/ckfinder/userfiles/files/xegalabasakunezijetawi.pdfIn PDF document text
    • http://bafiti.com/sklep/userfiles/file/32719034900.pdfIn PDF document text
    • http://airmon.hu/images/files/6100389928.pdfIn PDF document text
    +11 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0004f873.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4F873 10832 bytes
SHA-256: 425ed65f2ca8b899dbbcb887dda9c730f5da4df1834a32c791846c7b6394ad08
font_01_sfnt_off00051153.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x51153 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_02_sfnt_off0005287a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5287A 18768 bytes
SHA-256: 2f8027b898d7610e90145b518537e90576270a47474798fce390447cdfc77e03