Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2d163556dcb93a5…

MALICIOUS

PDF

581.0 KB Created: 2022-03-01 07:56:31 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-07-11
MD5: f5fb209efeeb921486373a3ae8e94d09 SHA-1: a1e301db963926dac19cfd446873d37ded9c059f SHA-256: e2d163556dcb93a5dd3b76ac2c777d508e155b9e0db7fd6f82dc83bd7536cc97
136 Risk Score

Machine Learning

  • Nyx PDF Classifier suspicious score 0.3336

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://tevav.co.za/XSRYdR1H?utm_term=imperative+verb+forms+in+german PDF link annotation
    • http://f-kcc.jp/user_data/userfiles/files/67661634347.pdfIn PDF document text
    • http://lalitas-thaimassage-spa.de/wp-content/plugins/formcraft/file-upload/server/content/files/16218853b10cb9---54171472863.pdfIn PDF document text
    • http://vincitydata.com/uploads/ckfinder/files/sojezesida.pdfIn PDF document text
    • https://poetnazrul.com/kcfinder/upload/files/62684909732.pdfIn PDF document text
    • https://shop-ecobati.com/medias/upload/files/julapaketo.pdfIn PDF document text
    • https://topas-septiki.com/media-temp/img/uploads/files/66625254888.pdfIn PDF document text
    • http://uitvaartverzorgingsindex.nl/images/uploads/38095514798.pdfIn PDF document text
    • http://eepr.cz/upload/files/2716036505.pdfIn PDF document text
    • http://pasarantogel2.com/contents/files/povuvidas.pdfIn PDF document text
    • http://cascad-trans.ru/files/xabozuzexuxujikasavuvabe.pdfIn PDF document text
    • https://yingzhaoliuart.com/upload/file/45358289338.pdfIn PDF document text
    • http://l-max.ru/userfiles/file/10310666509.pdfIn PDF document text
    • http://tehnaplus.mk/tehnaplus/kcfinder/upload/files/vovopiw.pdfIn PDF document text
    • http://skinct.com/upload_file/file/Fl202202111350496672.pdfIn PDF document text
    • https://kochitaxirental.com/ckfinder/userfiles/files/6712105484.pdfIn PDF document text
    • http://matstravel.ru/userfiles/file/xutaxajonetidebegijiwux.pdfIn PDF document text
    • http://ohxto.com/uploaded_files/userfiles/files/84312678600.pdfIn PDF document text
    • http://topflexsports.com/uploads/weguwoxamavobemisodopazo.pdfIn PDF document text
    • https://conrays.ru/f/data/wizobebu.pdfIn PDF document text
    • http://paten.kuduskab.go.id/packages/upload/kcfinder/upload/files/82243931242.pdfIn PDF document text
    • http://sinners-party.de/media/file/92818568270.pdfIn PDF document text
    • https://gs-hemeringen.de/ablage/userfiles/files/45410373058.pdfIn PDF document text
    • http://boxerdapolenta.com/cmsimple/images/file/62462794929.pdfIn PDF document text
    • http://tai-group.com/upload/files/sazujewari.pdfIn PDF document text
    • http://etiquettes-adhesives-bobine.fr/kcfinder/upload/files/183495606.pdfIn PDF document text
    • https://jdbailbonds.com/wp-content/plugins/super-forms/uploads/php/files/c3fee4debbc1eeb2634fb0724267a44f/zagutufuxelinuwu.pdfIn PDF document text
    • http://purepoem.com/resource/docContentImg/file/2022-02-04/a190c3807eeca3c1133cda7670870ee7.pdfIn PDF document text
    • http://esebtekstil.com/resimler/files/87188783310.pdfIn PDF document text
    • http://cmcthailand.com/ckfinder/userfiles/files/guripuwiluvirogiremawug.pdfIn PDF document text
    • http://gancza.pl/userfiles/file/xavivulomozabi.pdfIn PDF document text
    • https://yarsan.ru/wp-content/plugins/super-forms/uploads/php/files/4b3c6fce7701ecc18858c7ec38215d14/31410339354.pdfIn PDF document text
    • http://f-okinawa.com/img/tmp/files/2611498394.pdfIn PDF document text
    • https://mavismanagement.com/wp-content/plugins/formcraft/file-upload/server/content/files/162186396bfe18---76044945827.pdfIn PDF document text
    • https://www.unicodesystems.com/wp-content/plugins/super-forms/uploads/php/files/crvqpi5fqt1f401j19818lqmq3/wizuto.pdfIn PDF document text
    • https://radmangroup-ye.com/rgfiles/file/65161643026.pdfIn PDF document text
    • http://lesybb.sk/userfiles/file/megesokigiwuzozap.pdfIn PDF document text
    • http://f-okinawa.com/img/tmp/files/27675940310.pdfIn PDF document text
    • http://audyt.rowerowaszkola.pl/imgturysta/files/45801341977.pdfIn PDF document text
    • http://retrievers.su/ckfinder/userfiles/files/bumidazuzaxusifin.pdfIn PDF document text
    • http://dorp.pl/userfiles/files/matufimekobiwegi.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off000899f3.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off000899f3.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000899f3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x899F3 10812 bytes
SHA-256: b1b38e35b4dc4880336c1cbacf3853607cfc7a03ef8625c7591486740510cdf6
font_01_sfnt_off0008b2ad.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8B2AD 22216 bytes
SHA-256: 6d70604893926ddce5c3bc3f73ac6182b817f45c494692c05c4756930c11cd10
font_02_sfnt_off0008ece6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8ECE6 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9