Malicious PDF — malware analysis report

Static analysis result for SHA-256 de59e3f714970b1d…

MALICIOUS

PDF

656.5 KB Created: 2021-04-09 18:49:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-06-04
MD5: b316c7ae2fa270066f641c0aa093f855 SHA-1: 2d388718808fdd2908b8c0999826c68a52b399c5 SHA-256: de59e3f714970b1d053465fc69fb092f10666aafe88277deff1f1aec725bea90
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with a detection name indicating it is a phishing trojan. The document body contains text related to a game crack, and an embedded URI points to a URL that also mentions a game crack, suggesting a phishing lure. The presence of numerous embedded URLs further supports the phishing attack pattern.

Machine Learning

  • Nyx PDF Classifier clean score 0.0131

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.natsihwa.org.au/sites/default/files/webform/17947704001.pdf In PDF document text
    • https://www.telluridescience.org/sites/default/files/tstc-applications/pagasumoxozodaxatukaliwus.pdfIn PDF document text
    • http://www.muttypawsacademy.com/sites/default/files/webform/vaccines/65827293628.pdfIn PDF document text
    • http://portal-mysigma.com/system/files/student-proof/41429692510.pdfIn PDF document text
    • https://www.woonsocketri.org/system/temporary/webform/kebadewanizokodijixupid.pdfIn PDF document text
    • https://www.cdcplumbing.com/sites/default/files/webform/contact-us/65589142167.pdfIn PDF document text
    • https://extranet.blanchisserie-toulousaine-de-sante.com/sites/extranet.blanchisserie-toulousaine-de-sante.com/files/documents/justificatifs/6659556688.pdfIn PDF document text
    • https://www.cdcplumbing.com/sites/default/files/webform/contact-us/sawifujemenolezaf.pdfIn PDF document text
    • http://cicatsalud.com/html/sites/default/files/webform/65000750087.pdfIn PDF document text
    • https://ambrose.edu/sites/default/files/webform/gewematumupam.pdfIn PDF document text
    • https://www.uts.cw/sites/default/files/webform/tidenopuzi.pdfIn PDF document text
    • https://www.telluridescience.org/sites/default/files/tstc-applications/30232074114.pdfIn PDF document text
    • http://www.pacificsportfraservalley.com/sites/default/files/webform/90877516301.pdfIn PDF document text
    • http://www.pacificsportfraservalley.com/sites/default/files/webform/banofamuwidobekoke.pdfIn PDF document text
    • http://www.typoland.com/http://www.typoland.com/designers/Lukasz_Dziedzic/CopyrightIn PDF document text
    • http://www.typoland.com/In PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.thdl.org/http://www.thdl.org/TibetanIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/YTWXjIUwRh0/uplcv?utm_term=mass+effect+3+invalid+cerberus+code+crackPDF link annotation
    • https://www.ice.cam.ac.uk/sites/www.ice.cam.ac.uk/files/webform/tivajojisepizoni.pdfIn PDF document text
    • https://campusrec.princeton.edu/system/files/webform/popikinof.pdfIn PDF document text
    • https://thesanfordschool.asu.edu/sites/default/files/webform/43157208480.pdfIn PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlTibetanIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0005e3b2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5E3B2 8476 bytes
SHA-256: 0837e9e137591910f86fec8b3b744f31fa5f8b55fc2c13fe69a1211abe3c3b9a
font_01_sfnt_off0005fa41.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5FA41 187048 bytes
SHA-256: 34f266d1c0240eca0998569004a7c4631f5135f314d718484a5c034125e133af
font_02_sfnt_off0008202a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8202A 6168 bytes
SHA-256: 50bd8db5ff9a0f03ea6ac0366ab4ff273dceb6ff0c6101ac0faff1fd52ccc92d
font_03_sfnt_off00082fcc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x82FCC 5332 bytes
SHA-256: c5f5400711dd571447bfb4c46a3a3c96124fe35261b8fb6187e32123187fc70e
font_04_sfnt_off000841fb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x841FB 8904 bytes
SHA-256: e1e5d19d16db50c630cb1365578f6dd9718eeff742a8a4519d283816eff0df5b
font_05_sfnt_off000853a7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x853A7 134784 bytes
SHA-256: 021cd3d5487286a76925076ef9fd923c49bc12cd94a83a5d8c4f98522291720e
font_06_sfnt_off0009cd97.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9CD97 15360 bytes
SHA-256: 056fb978cf6467ec5662b405f95dabcf3cf8512fc4c3bcd1b4b9572e7e693117
font_07_sfnt_off000a0047.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA0047 24536 bytes
SHA-256: 177d9830221da7795a44171d236b7f77e8718e557d4a8d088c566b9758a5c80c
font_08_sfnt_off000a2f3f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA2F3F 4324 bytes
SHA-256: 4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
font_09_sfnt_off000a3cfb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA3CFB 1736 bytes
SHA-256: 5095ccdfdd328c3f25b1766e9c65bca58fa839170fcb9f3db3c20e130d955aff