Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2d0d9dfedfbf1e7…

MALICIOUS

PDF

76.7 KB Created: 2022-04-04 23:01:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-07-11
MD5: ef13604cd2d2c35d4b3a54fe7e914bb3 SHA-1: ac8e19a5943ad1247ed3401f8dfd61aafc72acde SHA-256: e2d0d9dfedfbf1e7ef932dcff4d6cd0909bdde656d9b218da0e1d4479f7285de
186 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9973

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://delphin-restaurant.com/ckfinder/upload/files/76597625935.pdf In PDF document text
    • https://jawuzinirofona.weebly.com/uploads/1/3/4/8/134886132/bb5e3bbc1a.pdfIn PDF document text
    • https://zetolame.weebly.com/uploads/1/3/0/7/130775520/luvipa.pdfIn PDF document text
    • http://cadex-forensic.ch/app/webroot/kcfinder/upload/files/mibomafaremiduwaligo.pdfIn PDF document text
    • http://immodraft.nrw/images/architekten_agentur_images_/file/68487179985.pdfIn PDF document text
    • http://siciny.eu/userfiles/file/ziduxez.pdfIn PDF document text
    • http://www.bioderko.chodziez.pl/kcfinder/upload/files/repenunubiro.pdfIn PDF document text
    • https://nozirurabi.weebly.com/uploads/1/3/0/7/130738896/mutefixowese.pdfIn PDF document text
    • https://ludunijup.weebly.com/uploads/1/3/0/9/130968942/gizedimabesomu_gejagowet_nonisisal_lelegilakumuwe.pdfIn PDF document text
    • https://armature.ir/cache/fck_files/file/puwusezomulatodifodoz.pdfIn PDF document text
    • https://mudodawi.weebly.com/uploads/1/3/4/6/134653299/fevifakupuge.pdfIn PDF document text
    • https://kigolakelo.weebly.com/uploads/1/3/1/3/131380934/038a446650.pdfIn PDF document text
    • https://fupefodomixeja.weebly.com/uploads/1/3/4/8/134889506/1676775.pdfIn PDF document text
    • http://deauville.ru/files/file/wuvesisevenubapedekamonev.pdfIn PDF document text
    • https://kunizemofowirux.weebly.com/uploads/1/3/4/3/134311671/e8083d.pdfIn PDF document text
    • http://www.mkfilm.it/ckeditor/kcfinder/upload/files/78263395335.pdfIn PDF document text
    • https://wewiruvikaju.weebly.com/uploads/1/3/0/7/130775929/6177c32622b0e7.pdfIn PDF document text
    • http://bibikid.ru/upload/53650775666.pdfIn PDF document text
    • https://atavio.ru/files/file/3305917831.pdfIn PDF document text
    • http://ilpiccantino.it/admin/data/img/uploads/files/87233911787.pdfIn PDF document text
    • https://xesisawizes.weebly.com/uploads/1/3/1/6/131606125/4f935022702582.pdfIn PDF document text
    • http://norilskgu.ru/userfiles/file/fifisutupusitup.pdfIn PDF document text
    • https://xagajopudulu.weebly.com/uploads/1/3/4/6/134697977/lujalofu.pdfIn PDF document text
    • http://p-energo.ru/content/file/duriwejonaxugowis.pdfIn PDF document text
    • https://badakawage.weebly.com/uploads/1/3/0/9/130969543/sonafilonu.pdfIn PDF document text
    • https://colod.co.za/YmrXLWy8?keyword=when%20use%20functional%20programmingPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0000c71c.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0000c71c.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c71c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC71C 16924 bytes
SHA-256: e9b3c7204251a71bf6d3edfc4300623a741ee138b36c298167c7e1e8203e78b7
font_01_sfnt_off0000f370.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF370 11020 bytes
SHA-256: 672f07a7e30a4bcf91104551e53052c458a7b46566d190de6de6efe8886b72a9
font_02_sfnt_off00010cee.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10CEE 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1