Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea07ca8ba54df248…

MALICIOUS

PDF

556.3 KB Created: 2022-05-16 07:49:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-12
MD5: 59d15e2ecead4075465879a8755d6659 SHA-1: 234852a708737cdc5ef60dd803ac77ef4884f955 SHA-256: ea07ca8ba54df24850942399bfe1ac650e754ec4d0f342406502a6a88687d826
166 Risk Score

Machine Learning

  • Nyx PDF Classifier suspicious score 0.3455

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Travel-support phone-number stuffing scam critical SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lazav.co.za/XSRYdR1H?utm_term=girl+short+story+conflict+model+pdf+download+pc PDF link annotation
    • https://fakegakimebel.weebly.com/uploads/1/3/7/5/137506517/7e476c3d882c1.pdfIn PDF document text
    • http://sydjpg.com/images/upload/file/20220515_140902_172.pdfIn PDF document text
    • https://votuxujalesobe.weebly.com/uploads/1/3/4/6/134683371/04f23b4cf9c6.pdfIn PDF document text
    • http://visusmarble.com/images_upload/files/wizedelajevigemapobevo.pdfIn PDF document text
    • https://g-mtcc.com/motakamel/Ups/files/diwudedasadapevejurak.pdfIn PDF document text
    • https://nesibebinirudeb.weebly.com/uploads/1/3/5/3/135311353/5059554.pdfIn PDF document text
    • https://laval.gatr.ca/img/etablissements/files/posimowo.pdfIn PDF document text
    • https://jotevalosovem.weebly.com/uploads/1/3/4/3/134385082/4862853.pdfIn PDF document text
    • http://jin16888.com/userfiles/file/zubir.pdfIn PDF document text
    • http://realtor-madrid.com/uploades/fckeditorfile/napevirefosirasu.pdfIn PDF document text
    • https://demo-universal.order-pro.com/ckfinder/userfiles/files/91423695843.pdfIn PDF document text
    • https://worojuwoxalo.weebly.com/uploads/1/3/0/8/130814432/3357348.pdfIn PDF document text
    • http://zadonskiy.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16229be2a56459---mogewajulo.pdfIn PDF document text
    • http://ateliergermain.club/sites/default/files/file/41020281475.pdfIn PDF document text
    • https://jaragamonobuwuf.weebly.com/uploads/1/3/5/3/135346236/revoba_kamajezo_gujetuparewa.pdfIn PDF document text
    • https://mizavujubamu.weebly.com/uploads/1/3/0/7/130775062/pituwifixexafulope.pdfIn PDF document text
    • https://semufukat.weebly.com/uploads/1/3/1/8/131857602/gudaju.pdfIn PDF document text
    • https://www.mobytec.com.br/mobytec/wp-content/plugins/formcraft/file-upload/server/content/files/162496d4b7b000---ralipataxilafeda.pdfIn PDF document text
    • https://tafajasezo.weebly.com/uploads/1/3/4/3/134312542/8711967b1be0d06.pdfIn PDF document text
    • https://thietkewebbacninh.com/webroot/img/files/83691206534.pdfIn PDF document text
    • https://faxitisisajidol.weebly.com/uploads/1/4/1/4/141416337/kiremogilufu-milarege-kuvajuda.pdfIn PDF document text
    • http://sportsbettingconsultants.net/cote_dor_import/admin/ckfinder/userfiles/files/pejoxodizidakisitugum.pdfIn PDF document text
    • https://tinedejoditof.weebly.com/uploads/1/3/5/9/135971312/rinumokinefa.pdfIn PDF document text
    • https://rifuladeva.weebly.com/uploads/1/3/4/7/134708585/6632371.pdfIn PDF document text
    • https://mebedepubini.weebly.com/uploads/1/3/0/8/130813558/mopibumegigito.pdfIn PDF document text
    • http://tatnhapkhau.com/ckfinder/userfiles/files/74673373573.pdfIn PDF document text
    • https://depemazijibibo.weebly.com/uploads/1/3/4/8/134846300/sekezolisopos_kivul_kemobewi.pdfIn PDF document text
    • https://sizelomola.weebly.com/uploads/1/3/4/6/134606864/9461202.pdfIn PDF document text
    • https://vekoliro.weebly.com/uploads/1/3/4/4/134482952/7766946.pdfIn PDF document text
    • http://xn--80adib9cjd8a5e.xn--p1ai/i/upload/files/80135726094.pdfIn PDF document text
    • http://www.cuerpomenteyespiritu.es/wp-content/plugins/formcraft/file-upload/server/content/files/16277170a1e14f---62222177918.pdfIn PDF document text
    • https://bitoranajezope.weebly.com/uploads/1/3/1/4/131453137/3ba820d59826.pdfIn PDF document text
    • http://fanti-fitness.pl/uploads/assets/file/demimokinubawese.pdfIn PDF document text
    • https://zixavuxo.weebly.com/uploads/1/3/1/3/131398386/2780044.pdfIn PDF document text
    • https://derelegog.weebly.com/uploads/1/3/4/3/134339552/wogunegorurutem.pdfIn PDF document text
    • http://imagespa.mx/wp-content/plugins/formcraft/file-upload/server/content/files/1627a51a2ba3ac---fomilalitomijudesala.pdfIn PDF document text
    • http://kashima.cc/userfiles/file/85165127838.pdfIn PDF document text
    • https://zexorekimapuwip.weebly.com/uploads/1/3/4/7/134702453/2216286.pdfIn PDF document text
    • http://kanoonkaraj.ir/dbmanager/filebank/htmlgallery/file///bekujedaw.pdfIn PDF document text
    • http://technocom.pl/editor/file/27612760748.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0008288b.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0008288b.bin)

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0008288b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8288B 11124 bytes
SHA-256: 762b07ec427125f2d15739c33988ee475a25251503ffcbd276c06156b8e80003
font_01_sfnt_off00084273.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x84273 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off00085a8a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x85A8A 18040 bytes
SHA-256: 4fa15dfd5eebcc07b556eec6dfe53f0c1c4ec4ed8081af74f682169060cdfde3
font_03_sfnt_off0008899b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8899B 16324 bytes
SHA-256: 4a1e3041f8103a7d4e2e75db273aef650521616ab0c63d2aa14cc79fae449a56