Malicious PDF — malware analysis report

Static analysis result for SHA-256 de4749b902bb9163…

MALICIOUS

PDF

71.9 KB Created: 2020-12-18 21:50:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-04-03
MD5: 0de06295fa550cd23ce03a568a73052b SHA-1: 41f12e71a338c5588b6366220c0bcc8924a778d2 SHA-256: de4749b902bb9163949280f3f81dafabd7b5b7e546c4ac75fd43922cd69734da
136 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/wb?keyword=zombie%20outbreak%20simulator PDF link annotation
    • https://s3.amazonaws.com/jinabom/kotor_2_influence_guide_mira.pdfIn PDF document text
    • https://s3.amazonaws.com/jijari/35579574753.pdfIn PDF document text
    • https://s3.amazonaws.com/fedufiporara/b._com_degree_certificate_form.pdfIn PDF document text
    • https://s3.amazonaws.com/punurum/walovetibuxadir.pdfIn PDF document text
    • https://s3.amazonaws.com/sisaxu/98055477110.pdfIn PDF document text
    • http://www.ascendercorp.com/In extracted file (font_00_sfnt_off0000c75a.bin)
    • http://www.ascendercorp.com/typedesigners.htmlIn extracted file (font_00_sfnt_off0000c75a.bin)
    • https://uploads.strikinglycdn.com/files/f76c4d1a-408c-4554-b927-5d40c20cff3c/what_channel_is_gsn_on_fios.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ca4e1fe4-0c37-42e6-8854-be9da9fc6568/naruto_ep_25_bg_audio.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9d498757-4cb7-4518-a1a4-bb947f734795/34658176892.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc4d2cadf132613bbd6bc3a/t/5fcb9fc6551bdc47e7abe76d/1607180231077/zametusibotutapafatur.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/51099862-08b8-4c92-93ca-9401b4355f48/63628952769.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3964b477-0c1d-4b9a-86c4-980f9644da99/tejuloduboraru.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc0e7b740f1034a5ca8d025/t/5fc7a6520791337046ec3fd7/1606919764455/60178846284.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8e475e9a-466c-43f8-a319-159c09c5986a/98780201885.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn extracted file (font_00_sfnt_off0000c75a.bin)
    • http://dejavu.sourceforge.netIn extracted file (font_02_sfnt_off0000fdaa.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_02_sfnt_off0000fdaa.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c75a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC75A 4992 bytes
SHA-256: 728cd471cc7a0c2a1be0723ce2419b46237e265b21ca944764ddd93a26de9989
font_01_sfnt_off0000d83c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD83C 11176 bytes
SHA-256: 89d3008c50c125ce332e39d109ba75f5d589016f40f50013917a32a8a221a720
font_02_sfnt_off0000fdaa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFDAA 16068 bytes
SHA-256: 2e6efdb6ec6b06881b73571a6dc11127da1b4fc0f11d045bd7c2e12cbfc92ea6