Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d3000f1ecf546d8…

MALICIOUS

PDF

73.9 KB Created: 2021-04-07 18:48:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 10c91f428bbda1f149360ca11747eae2 SHA-1: bbf8e00608e16029d9de809560c1c6dbca735fcf SHA-256: 0d3000f1ecf546d86d5199157538ed0dfc4140362be885c2fd0ad234f55cbb29
98 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • ClamAV scan did not complete info CLAMAV_SCAN_INCOMPLETE
    ClamAV scan on this file did not complete (ClamAV error (exit 2)); the verdict reflects only static heuristics. The result is not cached so a later submission will retry the scan.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/123?utm_term=wedding+escort+cards+template+free
    • https://cdn.sqhk.co/kadefowuvun/5idXf8n/14516423290.pdf
    • https://xowogibudul.weebly.com/uploads/1/3/4/4/134446034/61e55.pdf
    • http://taxavifosobedul.iblogger.org/zefavuwubiri.pdf
    • https://cdn.sqhk.co/vomemubevu/9jjhbjh/xexudipudurogafujurolo.pdf
    • https://tamukatiraf.weebly.com/uploads/1/3/4/7/134766395/c5b3a8fe11.pdf
    • https://dorulitonen.weebly.com/uploads/1/3/1/3/131380258/8139509.pdf
    • https://cdn.sqhk.co/dufukeraj/ic9YHuL/telemedicine_appointment_nyc.pdf
    • https://jovinafunen.weebly.com/uploads/1/3/2/6/132695325/suzamugosusesatobivu.pdf
    • https://cdn.sqhk.co/patagarinixa/iiialig/versace_chain_reaction_shoes_grey.pdf
    • https://tatedamemod.weebly.com/uploads/1/3/0/7/130739791/4869141.pdf
    • https://siluxukazikuwo.weebly.com/uploads/1/3/5/3/135326211/9506885.pdf
    • https://uploads.strikinglycdn.com/files/7816ac8c-32ac-4f3c-945c-f15d88084613/what_is_my_sexuality_test_for_guys.pdf
    • https://0502d5d0-a0f5-47b8-bc1c-644c46e4e431.filesusr.com/ugd/6cabbb_a976e5314938417eb3413e0a457170bd.pdf?index=true
    • https://uploads.strikinglycdn.com/files/2b60244b-3a03-44eb-a84a-951ff02e758f/tc_renegade_54_cal_barrel.pdf
    • http://gunerepulesin.rf.gd/similarities_between_evolutionary_and_revolutionary_socialism.pdf
    • https://uploads.strikinglycdn.com/files/6412cb24-09ea-4b7f-a788-e710d7a94df2/gererovobanodozawix.pdf
    • https://uploads.strikinglycdn.com/files/fdff3e28-149b-4c14-ad1c-b4d774ea4dc1/sql_fundamentals_oracle.pdf
    • http://dululelafekupas.rf.gd/wavowazogixi.pdf
    • https://db38eef3-7d65-43a4-badd-ba39ed7d9417.filesusr.com/ugd/bd2483_54ff87f4d4e04f3fb92e2051344b18da.pdf?index=true
    • https://uploads.strikinglycdn.com/files/75ef2457-7069-4722-a975-b6be98b732fd/ukulele_club_of_santa_cruz_songbook_2.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/