Malicious PDF — malware analysis report

Static analysis result for SHA-256 dddc7228f3c5e117…

MALICIOUS

PDF

148.9 KB Created: 2022-05-07 00:28:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-07-16
MD5: 979bbef5eaf6f4241fde5a94e39f93bd SHA-1: 1c6b8ae1476067d294ac8283d09dd2503f310457 SHA-256: dddc7228f3c5e117f6c4448693954df50b9c3e73d033003c8c63bc55ebdc812e
181 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9391

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • PDF advertises pirated movie streaming/download medium PDF_PIRACY_STREAMING_LURE
    PDF rendered text advertises free full-movie streaming or download using piracy-brand names or a 'full movie + download/free/watch' intent phrase — recovered after folding the styled Unicode confusables the campaign uses to hide those keywords from plain-text detection. These are disposable SEO-spam carriers that route users to malvertising, fake-player, and scam pages; the PDF itself is inert.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://sunuf.co.za/XSRYdR1H?utm_term=the+sacrificial+egg+by+chinua+achebe+summary+pdf+full PDF link annotation
    • https://vifoluliguj.weebly.com/uploads/1/3/1/4/131437350/tubijolokar_xomexedabu_libim.pdfIn PDF document text
    • http://www.onegelha.com/wp-content/plugins/super-forms/uploads/php/files/51dedab371d5797720f7ec5588aea8a0/11531366984.pdfIn PDF document text
    • https://xibuzapesajeg.weebly.com/uploads/1/3/4/2/134236274/vibesovibi_posijo_fogunilen_kofojew.pdfIn PDF document text
    • http://mpapir.ekopapir.com/images/files/83175038153.pdfIn PDF document text
    • https://tukareteran.weebly.com/uploads/1/3/5/3/135307171/da4746061.pdfIn PDF document text
    • https://alertsecurity.in/ckfinder/userfiles/files/76173669979.pdfIn PDF document text
    • https://thepainter.asia/upload/files/giwekosise.pdfIn PDF document text
    • https://soudurelausiere.ca/upload/editor/file/31292902347.pdfIn PDF document text
    • https://pufopobumosuv.weebly.com/uploads/1/3/0/7/130776602/6537047.pdfIn PDF document text
    • https://bekonerotukabi.weebly.com/uploads/1/3/4/3/134366377/4649936.pdfIn PDF document text
    • https://www.bountyvacation.com/wp-content/plugins/formcraft/file-upload/server/content/files/1620d9b503f8d9---72814028265.pdfIn PDF document text
    • http://asqcert.net/files/files/fakoso.pdfIn PDF document text
    • https://guvufusefek.weebly.com/uploads/1/3/1/0/131070011/5202165.pdfIn PDF document text
    • https://bofakodejo.weebly.com/uploads/1/3/4/2/134265658/0cd31be8f.pdfIn PDF document text
    • https://doluhosting.com/calisma2/files/uploads/wifabe.pdfIn PDF document text
    • https://thebillionbottom.com/business_school/uploads/file/89323066664.pdfIn PDF document text
    • https://jedidaril.weebly.com/uploads/1/3/4/6/134687024/duroxugexajovavosezi.pdfIn PDF document text
    • https://cooperadora.grupocreartel.com/documentos/archivos/totaropos.pdfIn PDF document text
    • https://777mto.net/contents/files/44706616285.pdfIn PDF document text
    • https://femimujuzo.weebly.com/uploads/1/3/4/6/134640298/8761952.pdfIn PDF document text
    • http://firstcuwire.com/file_media/file_image/file/rukunalemokawajetolon.pdfIn PDF document text
    • https://wentworthre.com/wp-content/plugins/super-forms/uploads/php/files/2b3365ff7763c4f3f6429a704a8627e1/23538129738.pdfIn PDF document text
    • https://www.photosenpoesie.fr/ckeditor/kcfinder/upload/files/25604233939.pdfIn PDF document text
    • http://lynxauto.ru/userfiles/file/zejimudorupusepezezuzowo.pdfIn PDF document text
    • https://gelujesu.weebly.com/uploads/1/3/4/8/134847850/924702.pdfIn PDF document text
    • https://bibliotheque.ville.deux-montagnes.qc.ca/ckfinder/userfiles/files/27847649635.pdfIn PDF document text
    • http://rogatka.osieczna.eu/userfiles/file/60274402285.pdfIn PDF document text
    • http://www.stts-tir.com/admin/kcfinder/upload/files/dubutovokedezuvebedekoxi.pdfIn PDF document text
    • https://vimugowome.weebly.com/uploads/1/3/4/3/134323071/4c0385a187.pdfIn PDF document text
    • https://autoserviziparlatore.it/filesUploads/file/8467588275.pdfIn PDF document text
    • http://haozuowenwang.com/imagefiles/file/jaxasilot.pdfIn PDF document text
    • https://10fci.net/userfiles/file/mixafipinuvorobawop.pdfIn PDF document text
    • https://fedalovojuxunod.weebly.com/uploads/1/3/0/7/130775560/zunuzagafafomimefezo.pdfIn PDF document text
    • https://sobolone.weebly.com/uploads/1/3/0/7/130775045/ef4ad04320519.pdfIn PDF document text
    • https://bumekeri.weebly.com/uploads/1/4/1/5/141516306/serax_kuxigu_wuniwameme_letafimebunem.pdfIn PDF document text
    • https://ravemusasejiw.weebly.com/uploads/1/4/1/3/141301444/9019240.pdfIn PDF document text
    • http://mh-gartengestaltung.de/userfiles/file/15623804560.pdfIn PDF document text
    • https://toromadon.weebly.com/uploads/1/3/4/5/134523466/3663361.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0001e357.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0001e357.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001e357.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1E357 11168 bytes
SHA-256: b065d6d6533c5c1460448aaa3dc9f274163517d5b25ef94464f427bc2e002106
font_01_sfnt_off0001fcd1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1FCD1 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off000214e3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x214E3 18644 bytes
SHA-256: 4291332c21f4692ebbba3ff66c9692f538e1c5e36f7e6a6e098bc2529c378f6c