Malicious PDF — malware analysis report

Static analysis result for SHA-256 437a4f048fcdebd4…

MALICIOUS

PDF

88.7 KB Created: 2021-03-16 12:43:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0dcf76f90b36c6db4deca5865453161a SHA-1: de6da1741846bd873d1e907bfc3f3e158c72b859 SHA-256: 437a4f048fcdebd4c61368b14cb873cafdc0ebd975c7054c48d231ebb2948835
138 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • ClamAV scan did not complete info CLAMAV_SCAN_INCOMPLETE
    ClamAV scan on this file did not complete (ClamAV error (exit 2)); the verdict reflects only static heuristics. The result is not cached so a later submission will retry the scan.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/strik?utm_term=what+is+a+female+alpha%2527s+mate+called
    • http://uniques.space/bts_burn_the_stage_subtitle_indonesia8ecmd.pdf
    • https://cdn-cms.f-static.net/uploads/4491155/normal_60460a5e1b243.pdf
    • https://cdn-cms.f-static.net/uploads/4490949/normal_5fe8f66079fc9.pdf
    • https://cdn-cms.f-static.net/uploads/4380078/normal_6032bc3732b5f.pdf
    • https://cdn-cms.f-static.net/uploads/4465703/normal_5fd202e16ff63.pdf
    • http://confirmationhelpcenter.com/36560378662a3mqh.pdf
    • https://xufetujada.weebly.com/uploads/1/3/4/7/134745175/4462144.pdf
    • https://cdn-cms.f-static.net/uploads/4484370/normal_603603259beaf.pdf
    • https://static.s123-cdn-static.com/uploads/4468831/normal_60060efa1a433.pdf
    • https://cdn-cms.f-static.net/uploads/4419198/normal_601e73d261aed.pdf
    • https://static.s123-cdn-static.com/uploads/4386089/normal_5fcee1f1c4f3b.pdf
    • https://cdn-cms.f-static.net/uploads/4404730/normal_600a662f806cc.pdf
    • http://twoup-viktoria.online/how_to_set_citizen_perpetual_calendar_watchibkb5.pdf
    • https://doxazefeseremef.weebly.com/uploads/1/3/4/7/134764644/e8e0adb19261.pdf
    • https://jimozesixumuwis.weebly.com/uploads/1/3/4/5/134508673/ff30eb0.pdf
    • https://cdn-cms.f-static.net/uploads/4415327/normal_604cd321be04d.pdf
    • https://cdn-cms.f-static.net/uploads/4383308/normal_60222d65ea865.pdf
    • https://cdn-cms.f-static.net/uploads/4491155/normal_
    • https://52a72965-a6d2-471e-b66a-59a59a4d663b.filesusr.com/ugd/e643da_d94373a95552475db714c705e78eebff.pdf?index=true
    • https://8d40832c-2e2b-4284-8151-bb35a16d80ac.filesusr.com/ugd/05d014_52965929f92546a6bc63ada611b09c3a.pdf?index=true
    • https://dedb376b-efc3-4528-ac10-fc65d12f866c.filesusr.com/ugd/5f6074_c5c1f79870e447d9891570b6a58d9f1d.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/