Malicious PDF — malware analysis report

Static analysis result for SHA-256 77e61cc3695fd2c5…

MALICIOUS

PDF

76.3 KB Created: 2021-03-29 06:39:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1010d3798d1e1cdf6dc33660fb72fa04 SHA-1: 9621ed49a65fb72689113f9ab93513370c638065 SHA-256: 77e61cc3695fd2c54850fff6289ae31d994efc976caa8c0210674dc1ee89d10f
98 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • ClamAV scan did not complete info CLAMAV_SCAN_INCOMPLETE
    ClamAV scan on this file did not complete (ClamAV error (exit 2)); the verdict reflects only static heuristics. The result is not cached so a later submission will retry the scan.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/aws?utm_term=how+to+tell+if+a+molecule+has+a+zero+dipole+moment
    • http://frut-tree.site/87299576622psg87.pdf
    • http://romigeguwapefi.22web.org/vodajanavutojinujit.pdf
    • http://azakalaza5.xyz/jubagunedafogezal90mt9.pdf
    • http://50offit.pro/35339009012gfj7.pdf
    • http://lifupodez.22web.org/15684502124.pdf
    • http://modernstyle.pro/2446445659bxkus.pdf
    • https://7fad2989-91b8-457c-89bc-9a0e7aeef19f.filesusr.com/ugd/b03ff3_0eb7cf6fbded40b38c7e7aa2a22ada46.pdf?index=true
    • http://golagesobowe.epizy.com/kubota_bx_backhoe_specs.pdf
    • https://uploads.strikinglycdn.com/files/93c68b22-fbec-4fd2-8698-1b251924e61c/tizimuwunirijen.pdf
    • https://uploads.strikinglycdn.com/files/b6b12205-3bc3-4c4d-b47b-382562c6be38/lomezowele.pdf
    • https://uploads.strikinglycdn.com/files/3ec5e126-1754-4178-b84b-465df12f52c3/70517184153.pdf
    • http://pamikope.epizy.com/id_requirements_for_nys_drivers_permit.pdf
    • https://s3.amazonaws.com/zubata/43187878303.pdf
    • https://s3.amazonaws.com/bovenotojitowe/film_avatar_2009_mp4.pdf
    • https://uploads.strikinglycdn.com/files/12c082a3-78df-4031-8169-f9550ff42001/what_can_you_do_with_a_degree_in_international_business.pdf
    • http://kolixuvurivol.epizy.com/interior_design_book.pdf
    • https://uploads.strikinglycdn.com/files/aa69154f-d717-4cf7-82e6-892260d4b3f1/2149515780.pdf
    • https://s3.amazonaws.com/zuwimadaneb/the_quran_in_english_app.pdf
    • https://8d928d4c-4e32-4dc6-8093-d383c90b3cca.filesusr.com/ugd/b5d49c_432d50d2b59e42219a7d3004cfc89ca9.pdf?index=true
    • https://uploads.strikinglycdn.com/files/bb52ec33-3e63-4f2d-855a-40eb0429559c/lonely_planet_costa_rica_free_download.pdf
    • https://uploads.strikinglycdn.com/files/211156c0-db3a-49d9-9250-a16f6d366640/como_convertir_un_archivo_a_word_en_linea_gratis.pdf
    • https://1ee34b3e-bfcb-4e25-b227-79ffd44eef10.filesusr.com/ugd/9d5096_b8652915a5ed4b15b73774628314ec77.pdf?index=true
    • https://s3.amazonaws.com/pewebopufupe/91078499691.pdf
    • https://uploads.strikinglycdn.com/files/be02f31b-85e1-4a96-920b-25c3d2ec7787/9157680854.pdf
    • https://uploads.strikinglycdn.com/files/fe3c8507-8eb2-48ec-ae25-cc713eb1ec16/la_carta_de_juan_gabriel_desde_el_infierno.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/