Malicious PDF — malware analysis report

Static analysis result for SHA-256 46736406a9394e5a…

MALICIOUS

PDF

77.8 KB Created: 2021-04-03 13:59:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 112b63ebdba0c1379b0750f327188de3 SHA-1: 26aaa41088e66c7a25f2d060fb99365daff27446 SHA-256: 46736406a9394e5aa3ffad4fd4b6897894fc2685b8d82aa972c4cf20fa0f3941
98 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • ClamAV scan did not complete info CLAMAV_SCAN_INCOMPLETE
    ClamAV scan on this file did not complete (ClamAV error (exit 2)); the verdict reflects only static heuristics. The result is not cached so a later submission will retry the scan.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=the+piercing+bible+pdf+free+download
    • https://cdn-cms.f-static.net/uploads/4426972/normal_6060893f14ca4.pdf
    • http://islta.fun/lubisoxevobiliregarifafoqbmh.pdf
    • http://lnstagramverifiedsbadgeform.com/data_science_course_in_bangalore_iiitffdcc.pdf
    • http://studytogether.fun/dojoru2v0qi.pdf
    • http://momentikshop.space/earned_it_from_the_fifty_shades_of_grey_soundtrack_the_weeknd_mp3_download6zx9w.pdf
    • http://itawegan.fun/why_is_my_samsung_gas_oven_not_heating3q3sr.pdf
    • https://cdn-cms.f-static.net/uploads/4392441/normal_6057b0aa5b639.pdf
    • https://cdn-cms.f-static.net/uploads/4406169/normal_605df40a7f5d3.pdf
    • https://cdn-cms.f-static.net/uploads/4420752/normal_600b34288daa2.pdf
    • https://static.s123-cdn-static.com/uploads/4368265/normal_5fccc2f73b307.pdf
    • http://predouche.xyz/what_is_the_towing_capacity_of_a_2005_dodge_ram_1500zcfhm.pdf
    • https://cdn-cms.f-static.net/uploads/4414689/normal_60418cf10d12a.pdf
    • https://cdn-cms.f-static.net/uploads/4476416/normal_601408ed3c97b.pdf
    • https://cdn-cms.f-static.net/uploads/4501204/normal_601eb4432ed6c.pdf
    • https://static.s123-cdn-static.com/uploads/4471706/normal_5fdf2bbd5fd12.pdf
    • https://static.s123-cdn-static.com/uploads/4471252/normal_5ffa431ddad3c.pdf
    • https://569e8712-2873-4b93-a654-ea71b6b809e3.filesusr.com/ugd/345929_f36c598319344d1093d2fcfcf11999cc.pdf?index=true
    • https://0778d94d-b67d-49c3-8f6f-43f52d6edec9.filesusr.com/ugd/b85eb0_897aeb6a27fc4dae86a5a690a659e7fe.pdf?index=true
    • https://891dfe3a-8969-4df2-b253-5ccc4ebbb7a0.filesusr.com/ugd/e66789_eddb603965684f46b1cf9c423ab750cf.pdf?index=true
    • https://9c50f6df-e9c1-453e-a208-eff1cefe231f.filesusr.com/ugd/44b3dc_6f4de0376cbb464c93a4c885a33ef5e5.pdf?index=true
    • https://df1882fa-13c5-42f1-8438-577935b594b9.filesusr.com/ugd/91932b_3b5feb65510d49799ab2ae3134d668cf.pdf?index=true
    • https://2cc12256-1025-444a-bacb-901a9f007bda.filesusr.com/ugd/d1fcfc_e6cb4a33de7c4db085056fd69843d628.pdf?index=true
    • https://0dc5016f-38c0-4e11-84f4-4717e3ef4ec7.filesusr.com/ugd/4fd84c_fff1f0abb17744d8bdb6f43c9db6adbc.pdf?index=true
    • https://5c90cfa9-af55-48e2-9430-1f3580382729.filesusr.com/ugd/e2b09b_77c64093cb2f4afead0b024794db0891.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/