Malicious PDF — malware analysis report

Static analysis result for SHA-256 fb089cc25b3ef979…

MALICIOUS

PDF

214.5 KB Created: 2022-03-19 19:50:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2026-05-04
MD5: ac543b43eb7441e43380b838fc081b73 SHA-1: e92c42092321499fdd307cc9183c6fa3f0dd7ee4 SHA-256: fb089cc25b3ef979ea1fd57fcc6b6a344d6469705fbc4a813fa33e9f0e609515
134 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.8150

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • SEO-redirector lure link (multi-word utm_term) low PDF_SEO_UTM_REDIRECTOR_LINK
    PDF contains a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the search-keyword gateway used by the 'free document download' phishing family. Surfaced as an IOC; on its own this is a low-confidence signal.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nationaalbeloningsonderzoek.com/nieuwsbrieven/berichten/69395301185.pdf In PDF document text
    • https://xn--80ab4bebq2d.xn--p1ai/upload/files/sapubamazojuletip.pdfIn PDF document text
    • http://diveblubari.it/custom/archivio/files/rusejagidijulubaliguxekan.pdfIn PDF document text
    • https://miamivanservice.net/wp-content/plugins/formcraft/file-upload/server/content/files/1622e376fde24c---44295086641.pdfIn PDF document text
    • https://funke.be/data/file/dakelojamosa.pdfIn PDF document text
    • http://secretsocietygroup.com/temp/vinney/HTML/userfiles/file/67962987468.pdfIn PDF document text
    • https://www.oceaniacroisieres.com/html/scripts/ckeditor/kcfinder/upload/files/vufigenibepajuranoxos.pdfIn PDF document text
    • http://schule.havonix.com/ckfinder/userfiles/files/66163273767.pdfIn PDF document text
    • http://www.birapart.com/wp-content/plugins/formcraft/file-upload/server/content/files/16202595aac8da---98668101730.pdfIn PDF document text
    • http://leviedelsignore.it/gallery/files/15752782262.pdfIn PDF document text
    • http://trevelsi.ru/ckfinder/userfiles/files/luxuxabuz.pdfIn PDF document text
    • http://aorganboys.handyfriendship.com/upload/files/56354650790.pdfIn PDF document text
    • https://www.ttmagazin.com/assets/admin/js/plugins/kcfinder/upload/files/26484253717.pdfIn PDF document text
    • https://myclubowners.com/userfiles/files/jonajojupaxogijezuzax.pdfIn PDF document text
    • http://operahazyborlovagok.hu/browser/files/wunawadota.pdfIn PDF document text
    • http://pulsrmedia.com/wp-content/plugins/formcraft/file-upload/server/content/files/1622c01924ed48---dewasederukuzukexageje.pdfIn PDF document text
    • http://spbmedaks.ru/sites/default/files/uploads/talofafukivuxu.pdfIn PDF document text
    • https://divinehm.com/ckeditor/kcfinder/upload/files/84971046268.pdfIn PDF document text
    • https://profitaler.com/UserFiles/file/47334294246.pdfIn PDF document text
    • http://drigungkagyurinchenpalbarling.org/upload/userfiles/files/72958605682.pdfIn PDF document text
    • http://aardbeienfeesten.nl/uploadimages/files/wixumari.pdfIn PDF document text
    • http://jhdljz.com/userfiles/file/1643851798.pdfIn PDF document text
    • http://mos-craciun-inchiriere.ro/fckfiles/file/vimufezavifolinibap.pdfIn PDF document text
    • http://acrclubinversores.com/files/galeria/files/55036557134.pdfIn PDF document text
    • http://sk4education.com/ckfinder/userfiles/files/83318067969.pdfIn PDF document text
    • http://gayaarchi.com/userfiles/file/20220317153045.pdfIn PDF document text
    • https://www.quartzlock.com/userfiles/files/vimovi.pdfIn PDF document text
    • https://bykevin.com/wp-content/plugins/super-forms/uploads/php/files/c92ef694d4fc50ce6fda9986719894b0/90064581477.pdfIn PDF document text
    • http://acutecardio.ru/sadm_files/10069686948.pdfIn PDF document text
    • http://pronobile.de/catalog/file/75169705735.pdfIn PDF document text
    • https://atlastoursntravels.com/userfiles/file/soweke.pdfIn PDF document text
    • http://groupburuemas1.com/contents/files/kolesidedipigosowigewiva.pdfIn PDF document text
    • http://davostravel.com/upload/files/4898595175.pdfIn PDF document text
    • http://khamranghaiphong.com/upload/files/53351281922.pdfIn PDF document text
    • http://mp-hd.de/data/aktualnosci_imgs/file/nefipanutudi.pdfIn PDF document text
    • https://fecuq.co.za/XSRYdR1H?utm_term=chromium++linux+debPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0002f430.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0002f430.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002f430.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2F430 15696 bytes
SHA-256: e0870a5f4158be3a2d43ecd68043252dbc22461d6e455bbc78c185440d5509cb
font_01_sfnt_off00031c12.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x31C12 10456 bytes
SHA-256: e4f4449d42083f102acc592584fe1370782b30f79ac7740e173bf212a8e896a5
font_02_sfnt_off0003338a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3338A 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9