PDF / .VIR static analysis report

Static analysis result for SHA-256 b520eb63547cc96c…

SUSPICIOUS

PDF / .VIR

295.7 KB Created: 2021-07-26 02:49:57 +02:00 Authoring application: elijaysab (via PDF Master 1.0.1) First seen: 2024-07-13
MD5: 16fd1011de7786d0f9d31c20c322b805 SHA-1: 20ab79cb9cfcedf20284450ddcd755f100fbedd7 SHA-256: b520eb63547cc96c3d97626c309bd02e75fd015e1cacfaabdcd673abf2696dc9
59 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0055

Heuristics 4

  • PDF links to disposable redirector campaign host medium PDF_DISPOSABLE_REDIRECTOR_CAMPAIGN
    PDF's outbound link points to a throwaway redirector domain that recurs as the sole redirect across a large family of otherwise unrelated spam PDFs (movie-piracy, affiliate, and viral-link lures). These domains appear on no reputable list and exist only to funnel openers into malvertising / scam / download chains.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bytlly.com/206rjk PDF link annotation
    • https://www.theironriverpioneer.com/advert/srpg-studio-activation-unlock-code-and-serial/In PDF document text
    • https://searchyours.in/advert/merry-go-round-panchenkopoly_official_b1ymmn-oc-imgsrc-ru/In PDF document text
    • https://gmbh-retter.de/advert/xl5-dsc_0235-imgsrc-ru/In PDF document text
    • https://proslasdigo.weebly.com/guadalajara-chivas-v-club-leon.htmlIn PDF document text
    • https://gmbh-retter.de/advert/yummy-lil-girls-2-screenshot_20181013-234507-imgsrc-ru/In PDF document text
    • https://designyours.fr/fr/en/advert/browning-superposed-serial-number/In PDF document text
    • https://foplittducte.weebly.com/mix-summer-boys-4-287-imgsrcru.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/75b55420-74c6-4863-b315-54ac96817f5f/GunsNRosesAppetiteforDestructioniTunesPlusAACM4A.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fde0ec6f-7200-4352-b919-e0194fcfb804/Russian-Teen-Model-rouogBujlRo-iMGSRCRU.pdfIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00001213.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1213 120540 bytes
SHA-256: 488c39c8ebaa668c39e716aa4d2ad50deff686dfe01a4cc362edb0293f942128
font_01_sfnt_off0000c0f7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC0F7 76772 bytes
SHA-256: 07ce6fea3c98bf59133021be55ce9147f9c26365efe580a2a4f82130ca697f54