PDF / .VIR static analysis report

Static analysis result for SHA-256 d4ed9933a7131812…

SUSPICIOUS

PDF / .VIR

301.5 KB Created: 2021-08-02 10:36:45 +02:00 Authoring application: morentaimm (via PDF Master 1.0.1) First seen: 2024-07-25
MD5: e507ef15c4084f7bdea438b4c20b25fd SHA-1: 4604b9eda385340d74956e3e83a9b51043fbb303 SHA-256: d4ed9933a7131812e13c39767dc5f900919142913dc4e2abc38de02c2dbfb47b
59 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0599

Heuristics 4

  • PDF links to disposable redirector campaign host medium PDF_DISPOSABLE_REDIRECTOR_CAMPAIGN
    PDF's outbound link points to a throwaway redirector domain that recurs as the sole redirect across a large family of otherwise unrelated spam PDFs (movie-piracy, affiliate, and viral-link lures). These domains appear on no reputable list and exist only to funnel openers into malvertising / scam / download chains.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bytlly.com/20yh0m PDF link annotation
    • https://www.kid2kid.ie/advert/girls-dan����a-sexy-15-screenshot_20201105-000710-imgsrc-ru/In PDF document text
    • https://jualbutuh.com/advert/������������-����-��������������������-p9144875-imgsrc-ru/In PDF document text
    • https://dysringtepon.weebly.com/uploads/1/3/8/5/138565835/usps20postal20exam20421.pdfIn PDF document text
    • https://higgs-tours.ning.com/photo/albums/girls-in-diaper-pull-ups-17-010-imgsrc-ruIn PDF document text
    • https://trello.com/c/ljBlH2pl/251-uriah-heep-����������������������������������������-1970-2008wbr-alac-tracks-losslessIn PDF document text
    • https://kit.co/atselola/free-download-better-fifa-12-full-version-for-windows-xp/free-download-fifa-1In PDF document text
    • https://lutapesking1981.wixsite.com/provattwinde/post/smoking-data-csv-pdfIn PDF document text
    • https://www.datawrapper.de/_/uhBW2/In PDF document text
    • https://kit.co/tergmokohip/the-otherside-realm-of-eons-repack/the-otherside-realmIn PDF document text
    • https://libertyattendancecenter1969.ning.com/photo/albums/boy-power-profile-05-romain-01-boypower-profile-5-013038-imgsrcIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00000aec.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xAEC 121620 bytes
SHA-256: 7f79b9a90341c97ca0d0d7d5e1ea93d97b2acfcc73b6a6bc72b43f19354e9039
font_01_sfnt_off0000bc3c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBC3C 76772 bytes
SHA-256: 07ce6fea3c98bf59133021be55ce9147f9c26365efe580a2a4f82130ca697f54