Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2dd12a7c3799d92…

MALICIOUS

PDF

247.8 KB Created: 2022-04-02 02:07:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-07-11
MD5: 29a65aff76ef69198fb38bcf9cf7a1a6 SHA-1: 38c6034c7e35b1edaf118c8cdeef56327a62571f SHA-256: e2dd12a7c3799d922169733f28913b0022bc81d55bc27c0386e6aa7bfb8f10f3
176 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9884

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Travel-support phone-number stuffing scam high SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://funovupudejo.weebly.com/uploads/1/3/4/4/134473131/8b3afa.pdf In PDF document text
    • https://javedipigusoxi.weebly.com/uploads/1/4/1/2/141279155/misugo.pdfIn PDF document text
    • https://kitigenuripoduj.weebly.com/uploads/1/3/1/0/131070171/fikejixenarik-zafel.pdfIn PDF document text
    • https://vavurozuzen.weebly.com/uploads/1/3/1/0/131070500/c57b1039ce46.pdfIn PDF document text
    • http://www.sm.ac.th/ckfinder/userfiles/files/1060086275.pdfIn PDF document text
    • https://posesisex.weebly.com/uploads/1/3/5/3/135332701/fasinunikoziwu-dotisekenizaro-zuwolusil.pdfIn PDF document text
    • https://pukukadusese.weebly.com/uploads/1/3/4/6/134666137/9345257.pdfIn PDF document text
    • https://daradila.weebly.com/uploads/1/3/1/4/131438164/sunosifadaf_kosipenif.pdfIn PDF document text
    • https://disaxugotusineg.weebly.com/uploads/1/3/1/8/131871710/texumamar.pdfIn PDF document text
    • https://quizai.com/uploads/files/xoxejoxolorirepidosemu.pdfIn PDF document text
    • https://vokavubibobudew.weebly.com/uploads/1/3/5/3/135316357/91b4a1c835f.pdfIn PDF document text
    • https://averakazan.ru/kcfinder/upload/files/67954191585.pdfIn PDF document text
    • https://dobre-akce.cz/media/files/file/48970900234.pdfIn PDF document text
    • https://zagiwutexava.weebly.com/uploads/1/3/4/5/134501554/wetidala.pdfIn PDF document text
    • https://zunitaxipef.weebly.com/uploads/1/3/1/3/131398356/sebajelibulem_xeviwodawape_miwixuputomafab_pukibemazup.pdfIn PDF document text
    • https://cam-ceeds.org/ckfinder/userfiles/files/repuvotiregozurifu.pdfIn PDF document text
    • http://thucphamchucnangmy.vn/uploads/files/wevepojavobigu.pdfIn PDF document text
    • http://cheliabinsk.realxenon.ru/uploads/files/balikexatiro.pdfIn PDF document text
    • https://semuvobe.weebly.com/uploads/1/3/0/9/130969465/27d30cda.pdfIn PDF document text
    • https://nijodumedogale.weebly.com/uploads/1/3/6/0/136082157/7187550.pdfIn PDF document text
    • https://yubit.co.za/YmrXLWy8?keyword=the%20lion%20the%20witch%20and%20the%20wardrobe%20pdf%20gutenbergPDF link annotation
    • https://fotovotujipibar.weebly.com/uploads/1/3/4/2/134267097/dimitid_gowefisiniw_faxaze.pdfIn PDF document text
    • https://bxthirteen.wpengine.com/wp-content/plugins/super-forms/uploads/php/files/73f772d12bd7ebbf384dec06b8a09904/19117310381.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off000372af.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off000372af.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000372af.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x372AF 17016 bytes
SHA-256: 7b4e4d8983a5cf2a23af628ee65d7c9c124aef021edbad00b0598694bed68661
font_01_sfnt_off00039f30.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x39F30 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off0003b747.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3B747 11020 bytes
SHA-256: d4b978e0f75b22a898f92e94e0243dae907e112967c5b132f6b9105f9be94792