Malicious PDF — malware analysis report

Static analysis result for SHA-256 db96bad1be8cbf0f…

MALICIOUS

PDF

79.0 KB Created: 2021-04-05 13:32:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 10139b83c3c0ab02ffff60c64ae27280 SHA-1: ae062d6e1484acc399a83d01518e105995dc0e97 SHA-256: db96bad1be8cbf0f92a2107f574f9a327833758e5c0419c346317c12575620ec
156 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • ClamAV scan did not complete info CLAMAV_SCAN_INCOMPLETE
    ClamAV scan on this file did not complete (ClamAV error (exit 2)); the verdict reflects only static heuristics. The result is not cached so a later submission will retry the scan.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/wix?keyword=taylormade+m5+fairway+adjustment+chart
    • http://vopugixeroramox.medianewsonline.com/7_canciones_populares_espaolas.pdf
    • https://sukizasatesez.weebly.com/uploads/1/3/4/6/134686833/5371401.pdf
    • https://bogezozoxo.weebly.com/uploads/1/3/4/4/134479702/wirovoturesowobux.pdf
    • http://carishr.com/53436264073grd1j.pdf
    • http://fesunasisodenod.getenjoyment.net/kayla_itsines_bbg_week_10.pdf
    • http://summ-green.fun/dabazosimugabibuvevujauwtsq.pdf
    • https://kuburabet.weebly.com/uploads/1/3/4/3/134362545/4f411.pdf
    • https://wigimosasalak.weebly.com/uploads/1/3/2/8/132814057/gugorasamadub-xotadaxaguzewa-zigolifumu.pdf
    • https://neremepapo.weebly.com/uploads/1/3/4/6/134653798/fffb6d2d27065bd.pdf
    • http://befujukipepejem.mygamesonline.org/nazijo.pdf
    • http://tovelksa.website/lederoduwad9a2x4.pdf
    • http://insurancecarusa.com/32769169502woiek.pdf
    • https://tapulebuzaxu.weebly.com/uploads/1/3/0/8/130814605/wasenag.pdf
    • http://white-x.fun/6003448407a9oty.pdf
    • https://5a060084-92f5-4e09-b02e-bbac8bb45871.filesusr.com/ugd/05c943_9478caac64304929bf7a3ab49cd78f47.pdf?index=true
    • https://089130c0-62ae-4bf1-a93c-656440fe8451.filesusr.com/ugd/738632_1542ba2c24f24ea1a060934f4c5d64f2.pdf?index=true
    • https://s3.amazonaws.com/kewakuko/ghost_power_book_2_last_episode.pdf
    • https://435a888a-8f80-410d-aa77-77edd6e4491d.filesusr.com/ugd/51fec0_b198a4e69e8547c58afe0b87d467112f.pdf?index=true
    • https://s3.amazonaws.com/lupuvogotog/20797216190.pdf
    • https://s3.amazonaws.com/jifesu/bollywood_films_box_office_report_2019.pdf
    • https://s3.amazonaws.com/geraromu/mefevafage.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/