Malicious PDF — malware analysis report

Static analysis result for SHA-256 53e8911799e3b37d…

MALICIOUS

PDF

69.0 KB Created: 2021-03-20 06:58:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 11c9eebfae4d998801ff0aa570fe0763 SHA-1: d64e88ead65c68f5de01cbd57e075c79204273fa SHA-256: 53e8911799e3b37d0baf86159bb1849b3064e727074b33a47121f298a5409925
98 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • ClamAV scan did not complete info CLAMAV_SCAN_INCOMPLETE
    ClamAV scan on this file did not complete (ClamAV error (exit 2)); the verdict reflects only static heuristics. The result is not cached so a later submission will retry the scan.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/123?utm_term=toyota+auris+touring+sports+2014+manual
    • https://static.s123-cdn-static.com/uploads/4379736/normal_5fff4fa642967.pdf
    • https://cdn-cms.f-static.net/uploads/4418993/normal_60111d96cbe5c.pdf
    • https://cdn.sqhk.co/xadakede/ijjiXgj/73934740882.pdf
    • https://cdn.sqhk.co/figegixo/4vjbifn/mufisafema.pdf
    • https://cdn.sqhk.co/ragonujip/jeiegcV/viponekolanulomixu.pdf
    • https://nupezodebugu.weebly.com/uploads/1/3/2/3/132302780/c954f3f63a.pdf
    • https://cdn-cms.f-static.net/uploads/4465557/normal_604e9777a8224.pdf
    • https://cdn.sqhk.co/rozesivotix/gjjeXA0/fojorakimotomerov.pdf
    • https://static.s123-cdn-static.com/uploads/4464330/normal_5feb1d1adbf8c.pdf
    • https://1a441fb4-51dd-4528-a053-eb59ff664e18.filesusr.com/ugd/43d9d5_b4dbf601a708416d8b2229a50d016568.pdf?index=true
    • https://s3.amazonaws.com/nilititonawafim/bheema_telugu_songs_ringtones_free.pdf
    • https://67d298e0-85f4-4ad4-bf36-e1ac857e42fc.filesusr.com/ugd/b6bf5b_9837cbca58e949f8bea5cc80ffa158a6.pdf?index=true
    • https://1923692e-f727-4f58-80a8-3583160180e3.filesusr.com/ugd/c4ccc4_283f18bb513b4fd895170f03117d72a6.pdf?index=true
    • https://c18d9829-3add-4afa-bc87-35007fe3998a.filesusr.com/ugd/70c1ec_4a6180f308e948b4bf94098b3c4b99bf.pdf?index=true
    • https://da5bec28-7969-4117-8ffb-5069fce5e80c.filesusr.com/ugd/31593d_61cc2174f1d449b5999d0ee722421de7.pdf?index=true
    • https://8533cbf3-c0d6-400c-bdf8-8ca38cf0242b.filesusr.com/ugd/135178_18b66631cd2343e2a679547a542a60a7.pdf?index=true
    • https://s3.amazonaws.com/debiwelof/16346421964.pdf
    • https://b81e1767-bb0d-4562-9f98-cfef66859bb1.filesusr.com/ugd/b48b60_0b7556b14c5348b3b928ba0a8976a2e5.pdf?index=true
    • https://700ceb37-22d2-47c5-9888-d858af679aee.filesusr.com/ugd/c345b0_4b7658f550174deeac7c77b3fd7b6966.pdf?index=true
    • https://6f0a1f77-3195-4c90-aae7-8e5805bb56bd.filesusr.com/ugd/f94fd0_7de38558f7d94a8bac1b294786335fa5.pdf?index=true
    • https://s3.amazonaws.com/niwotipugonuvoz/10027492853.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/