Malicious PDF — malware analysis report

Static analysis result for SHA-256 b771608f5121feeb…

MALICIOUS

PDF

81.8 KB Created: 2021-03-19 17:04:49 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0d82f848d4711944b6e03962524c827d SHA-1: d46ca3c5eb892fc178dc4eaec95ba02dce7d98ef SHA-256: b771608f5121feeb6a6434d52538330b92de2aa26d042e728321c592bd0f3bca
98 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • ClamAV scan did not complete info CLAMAV_SCAN_INCOMPLETE
    ClamAV scan on this file did not complete (ClamAV error (exit 2)); the verdict reflects only static heuristics. The result is not cached so a later submission will retry the scan.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/award?keyword=ca+foundation+course+books+pdf+icai
    • https://rivadosogub.weebly.com/uploads/1/3/4/8/134880553/vonemufunalulob.pdf
    • http://vubitim.sportsontheweb.net/85316318165.pdf
    • https://domafotenok.weebly.com/uploads/1/3/5/9/135973376/bupadud-xixikubo-bixizotonumuf.pdf
    • http://tadurarawi.mypressonline.com/pubaj.pdf
    • https://goduvozimaku.weebly.com/uploads/1/3/1/3/131380582/479c997.pdf
    • http://pevewoxoxup.scienceontheweb.net/english_story_easy.pdf
    • http://zifufarox.getenjoyment.net/anexo_1_icao.pdf
    • http://vijexibat.mywebcommunity.org/sizedegonaratuno.pdf
    • https://direwuberegenis.weebly.com/uploads/1/3/4/3/134361890/187529.pdf
    • http://vazawujuzu.sportsontheweb.net/beautiful_creatures_2_full_movie_online_free.pdf
    • https://uploads.strikinglycdn.com/files/49e7b5d9-08e2-455b-8fdf-4581c3ad259b/defugaxabaxogenovokipotu.pdf
    • https://uploads.strikinglycdn.com/files/6ba053f5-7aec-43bf-aa61-8c14f2b9e1b1/wenizabonetekuruma.pdf
    • http://nokejufesuw.atwebpages.com/lovub.pdf
    • https://77483064-5892-4b52-b419-66e751946b77.filesusr.com/ugd/ef7b09_dd0ac9bb31624c139257b4dabc454837.pdf?index=true
    • https://51956041-da35-40aa-96c1-085c1f47c80d.filesusr.com/ugd/e6e573_9946cd504f7f4b80952b6926e7e7056f.pdf?index=true
    • http://lurarapekakaka.atwebpages.com/19921769287.pdf
    • https://bc3ee532-4344-4262-9f0b-d8353e2229a5.filesusr.com/ugd/6ca3f6_154d28a970e44a108d6ce0f02cfb6117.pdf?index=true
    • https://f9c81679-ddb1-4746-ab40-32673edc426c.filesusr.com/ugd/2eff39_dc9c4cebb3214b58ae4d3c21654bec03.pdf?index=true
    • http://junenizexi.epizy.com/19321748013.pdf
    • https://uploads.strikinglycdn.com/files/b7754e5d-553f-4af4-9651-4a9b6a2f5231/biwijigusimuzerilugax.pdf
    • http://newewixojarulup.epizy.com/walt_disney_world_calendar_of_events_2020.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/