Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2d49b333ecfb9fd…

MALICIOUS

PDF

453.3 KB Created: 2022-03-23 09:55:59 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-07-11
MD5: aa1f76466ee5f63bd921fe275786ecc0 SHA-1: ee45180008a5b273d4ce512ef01ae0df698455a6 SHA-256: e2d49b333ecfb9fdbea622333ea055416f3721832b891daf34febc74359e58ed
161 Risk Score

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4858

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • PDF advertises pirated movie streaming/download medium PDF_PIRACY_STREAMING_LURE
    PDF rendered text advertises free full-movie streaming or download using piracy-brand names or a 'full movie + download/free/watch' intent phrase — recovered after folding the styled Unicode confusables the campaign uses to hide those keywords from plain-text detection. These are disposable SEO-spam carriers that route users to malvertising, fake-player, and scam pages; the PDF itself is inert.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://hvnepal.com/assets/kcfinder/upload/files/2126361586.pdf In PDF document text
    • http://flairpens.ru/uploads/file/jaferezuxuwifojo.pdfIn PDF document text
    • http://vietsecwindow.com/app/webroot/files/ckfinder/files/79035957965.pdfIn PDF document text
    • http://beerskiboot.de/img/upload/file/26646111932.pdfIn PDF document text
    • http://c-translations.com/data/upload/File/jalifebomojoxawosufebise.pdfIn PDF document text
    • http://xn--80aafjbaeihgganggf9ajkncugh2a.xn--p1ai/pict/file/bilasazeto.pdfIn PDF document text
    • https://www.officinadelgustoroma.com/wp-content/plugins/super-forms/uploads/php/files/7242372a7a31a8acbbc0400bc82c2d1f/73276634579.pdfIn PDF document text
    • http://www.teaterskolen-efteruddannelsen.dk/ckfinder/userfiles/files/82903514436.pdfIn PDF document text
    • http://tvcsoltau.de/userfiles/file/vuxetonazo.pdfIn PDF document text
    • https://callmarkinvestments.fortunekenya.com/callmark/files/93780119297.pdfIn PDF document text
    • http://immodraft.eu/images/architekten_agentur_images_/file/xigubawexili.pdfIn PDF document text
    • http://tamezou.com/upload/ckfinder/files/97232298436.pdfIn PDF document text
    • http://1666-3668.com/attach/userfiles/file/86419883519.pdfIn PDF document text
    • http://ingore.cn/upload/files/dawigiralepesob.pdfIn PDF document text
    • http://havefuntogether.com/image/upload/File/walewelokuketumikemawuniz.pdfIn PDF document text
    • https://mn-lawfirm.com/box/userfiles/file/51795031554.pdfIn PDF document text
    • https://1sis.com/wp-content/plugins/formcraft/file-upload/server/content/files/16231b24de1f93---vonodemipumebawude.pdfIn PDF document text
    • http://sdhmladavozice.cz/userfiles/file/7176810832.pdfIn PDF document text
    • http://strojsteel.cz/webpagebuilder/ckfinder/userfiles/files/kupireniju.pdfIn PDF document text
    • https://decisionstogo.com/fck_image/file/jefamiwuk.pdfIn PDF document text
    • https://amoslodge10-org.alljobsinliberia.com/ckfinder/userfiles/files/jujimifodolulatituwena.pdfIn PDF document text
    • http://omegabg.net/media/ck/files/83007897962.pdfIn PDF document text
    • https://ms02bet.com/contents/files/koxilexojuv.pdfIn PDF document text
    • http://www.norestim.ro/wp-content/plugins/formcraft/file-upload/server/content/files/16233ad38631b1---47595222763.pdfIn PDF document text
    • http://montaze.org/democms/userfiles/file/maponuwavosojus.pdfIn PDF document text
    • http://dkkarsin.pl/img/upload/files/wuwopixekujetusiwuva.pdfIn PDF document text
    • https://jung.su/kcfinder/upload/files/35405295585.pdfIn PDF document text
    • https://yoyep.co.za/XSRYdR1H?utm_term=pirates+of+the+caribbean+jarrod+radnich+sheet+music+free+pdfPDF link annotation
    • http://www.sarajevo-inn-grunewald.com/wp-content/plugins/formcraft/file-upload/server/content/files/162286c21dcc57---xugedofiragomebuf.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off00068873.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off00068873.bin)

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00068873.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x68873 16244 bytes
SHA-256: fddcbe21bdf9fb2753729b4ab5b26d7a3fbb01e3fe51d41ab0725360e25c189d
font_01_sfnt_off00069e5d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x69E5D 19624 bytes
SHA-256: f901cbc9e130e71e09de19ae23cbb6dafafa180179c1321fb24fc9710872f54f
font_02_sfnt_off0006d161.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6D161 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_03_sfnt_off0006e881.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6E881 11212 bytes
SHA-256: 1ae80a726d633fb2042f654605eb6ca21a016743b18d8d2e85fce8c5684f2c1e