PDF / .VIR static analysis report

Static analysis result for SHA-256 52de96e3302c7ced…

SUSPICIOUS

PDF / .VIR

307.6 KB Created: 2021-06-27 23:12:02 +02:00 Authoring application: rexleat (via PDF Master 1.0.1) First seen: 2024-05-12
MD5: e9a17b71a95b202d52435e2952ca2f9d SHA-1: 1063bcffd37bb6ed765ac60b8caaf5fe22bbb4ca SHA-256: 52de96e3302c7cedf029ccb9d9b4729585357a729c1e35f321220c9389976a41
54 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0060

Heuristics 4

  • PDF links to disposable redirector campaign host medium PDF_DISPOSABLE_REDIRECTOR_CAMPAIGN
    PDF's outbound link points to a throwaway redirector domain that recurs as the sole redirect across a large family of otherwise unrelated spam PDFs (movie-piracy, affiliate, and viral-link lures). These domains appear on no reputable list and exist only to funnel openers into malvertising / scam / download chains.
  • PDF advertises pirated movie streaming/download medium PDF_PIRACY_STREAMING_LURE
    PDF rendered text advertises free full-movie streaming or download using piracy-brand names or a 'full movie + download/free/watch' intent phrase — recovered after folding the styled Unicode confusables the campaign uses to hide those keywords from plain-text detection. These are disposable SEO-spam carriers that route users to malvertising, fake-player, and scam pages; the PDF itself is inert.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bytlly.com/1y6zs7 PDF link annotation
    • https://eridscootmil.weebly.com/uploads/1/3/6/2/136243944/ashlarvellum-cobalt-11-sp0-build-1111-with-activator-latest.pdfIn PDF document text
    • https://emtevibfu.weebly.com/uploads/1/3/6/4/136453947/octoplus-box-samsung-crack-screenl.pdfIn PDF document text
    • https://pnumegmauprac.weebly.com/uploads/1/3/6/5/136577096/the-ghost-in-the-graveyard-full-movie-download-in-hindi.pdfIn PDF document text
    • https://tsamacitnie.weebly.com/uploads/1/3/6/5/136590363/mission-mumbai-in-hindi-free.pdfIn PDF document text
    • https://stuptiwiting.weebly.com/uploads/1/3/6/4/136481238/ei-pothe-jokhon-ami-jai-mp3-song-29.pdfIn PDF document text
    • https://trello.com/c/SR1kmmt5/363-livecd-windows-xpe-7peIn PDF document text
    • https://trello.com/c/7Zo3o44n/149-tum-se-achcha-kaun-hai-hindi-movie-download-linkIn PDF document text
    • https://trello.com/c/lcbe5ii6/392-full-3-idiots-english-dubbed-torrentlIn PDF document text
    • https://contlisandce.amebaownd.com/posts/18881044In PDF document text
    • https://trello.com/c/QXQykv4a/159-free-tmpgenc-v256-keygenIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000019f5.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x19F5 120140 bytes
SHA-256: a217f12862e0ff75203bdd4136ca0d68471050be46bb09aed5306898926ffdd4
font_01_sfnt_off0000c7d8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC7D8 76772 bytes
SHA-256: 07ce6fea3c98bf59133021be55ce9147f9c26365efe580a2a4f82130ca697f54