Malicious PDF — malware analysis report

Static analysis result for SHA-256 db7110fccd407b55…

MALICIOUS

PDF

83.1 KB Created: 2021-03-21 09:49:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 11afe8ddc14f2b50dad7eb5990d4abb5 SHA-1: 6c53a67dc0095844e7f8eabf4b1e5d2eddb3d277 SHA-256: db7110fccd407b55642e1139636e24ba1a0257281fdbcec0e747f72bb1f83809
98 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • ClamAV scan did not complete info CLAMAV_SCAN_INCOMPLETE
    ClamAV scan on this file did not complete (ClamAV error (exit 2)); the verdict reflects only static heuristics. The result is not cached so a later submission will retry the scan.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/wix?keyword=android+cracked+apps+download+apk
    • https://cdn.sqhk.co/xoraxuvonaf/oopT4jh/death_road_to_canada_marathon_mode_tips.pdf
    • http://powuvomewekuxeb.getenjoyment.net/apiculture_book.pdf
    • https://cdn.sqhk.co/jegetito/jimBhem/niwakogesawujexizogavuw.pdf
    • http://xezawavebavulem.iblogger.org/hitachi_10_inch_miter_saw_with_laser.pdf
    • http://sinomefonok.mywebcommunity.org/sovuvaradoz.pdf
    • http://leporabev.mywebcommunity.org/75358479957.pdf
    • https://cdn.sqhk.co/madufuxenuw/8SwifUK/lightroom_app_free_download_for_windows.pdf
    • https://cdn.sqhk.co/kerosumumato/jaM9F23/42989163829.pdf
    • https://cdn.sqhk.co/tizudukokeni/qVibvje/music_video_editor_free_video_maker_videos.pdf
    • https://29ce6865-365c-47c4-9f0a-635d6f965865.filesusr.com/ugd/0d6b77_15526854df254509bb6dc0597887d010.pdf?index=true
    • https://uploads.strikinglycdn.com/files/2643089c-9859-4105-8587-602d25d32833/vigilapolapo.pdf
    • https://uploads.strikinglycdn.com/files/93cb2951-8e13-4d8d-bbd9-b19638954713/are_bostitch_and_dewalt_the_same_company.pdf
    • https://uploads.strikinglycdn.com/files/cbcc82ef-d901-48d9-8fbd-24227afdea4c/31354789204.pdf
    • http://turijebudeta.rf.gd/fleckney_primary_school_ofsted_report.pdf
    • https://s3.amazonaws.com/zakunafu/windows_media_player_windows_10_pro.pdf
    • https://s3.amazonaws.com/minabiwa/peter_drucker_management_tasks_responsibilities_practices.pdf
    • https://ae0ecf71-49bb-4ac4-bba4-d0f2a20d1af9.filesusr.com/ugd/668a47_0094892a8e884dba9a1b72ae60a23d20.pdf?index=true
    • https://cd9ed9ec-87d1-42be-9198-0b2de6c1db4d.filesusr.com/ugd/158fb9_013f0a2297924710b8335038506197be.pdf?index=true
    • https://ec451167-49e0-489e-a150-d7dc0ecf9264.filesusr.com/ugd/fe0276_806dbfed2ecf4effad8337344bef8a78.pdf?index=true
    • http://telagivepovadul.epizy.com/madurovasigiris.pdf
    • https://s3.amazonaws.com/kiguteperilodu/how_to_make_knex_pistol.pdf
    • https://uploads.strikinglycdn.com/files/2033abca-1347-4517-8310-27f099ff3773/mewivukewoparazoxuw.pdf
    • https://uploads.strikinglycdn.com/files/54258d50-e374-480c-b145-b1bd5ab52702/14302794908.pdf
    • https://55963656-6eb1-4b25-bcd5-bb835d65808b.filesusr.com/ugd/0064ae_2ae1c911a34a482f8be33a27dec0138c.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/