Malicious PDF — malware analysis report

Static analysis result for SHA-256 eac8d7f6703f4ead…

MALICIOUS

PDF

77.6 KB Created: 2021-03-10 04:45:42 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0e18d7ab09543da26bb30c5c878a587d SHA-1: 33fcc6672e3fde42b775589c75116d1d663a8013 SHA-256: eac8d7f6703f4ead782099304b5cf51306817915edc3a6dedca696af00f845d4
98 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • ClamAV scan did not complete info CLAMAV_SCAN_INCOMPLETE
    ClamAV scan on this file did not complete (ClamAV error (exit 2)); the verdict reflects only static heuristics. The result is not cached so a later submission will retry the scan.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/award?keyword=abide+with+me+chords+piano+pdf
    • https://cdn.sqhk.co/sogefuluf/Zhd3ijC/zotifezotuwe.pdf
    • https://cdn-cms.f-static.net/uploads/4452851/normal_5fdc871686424.pdf
    • https://static.s123-cdn-static.com/uploads/4499021/normal_5ff366ac8992d.pdf
    • https://static.s123-cdn-static.com/uploads/4496826/normal_6004e5b5cdddd.pdf
    • https://static.s123-cdn-static.com/uploads/4457272/normal_60065c075ab67.pdf
    • https://cdn.sqhk.co/fetumamuv/n6g8iaR/yellow_plastic_shopping_bags_wholesale.pdf
    • https://static.s123-cdn-static.com/uploads/4449990/normal_5fdf944c21f7d.pdf
    • https://cdn-cms.f-static.net/uploads/4407795/normal_5fd7971966bbd.pdf
    • https://static.s123-cdn-static.com/uploads/4467561/normal_5feeb32ad2031.pdf
    • http://pilefud.iblogger.org/duwatatidifujurifo.pdf
    • https://static.s123-cdn-static.com/uploads/4425921/normal_600258cdb4f03.pdf
    • https://uploads.strikinglycdn.com/files/4f992619-6d5a-492f-a37b-2cced2886159/83013247959.pdf
    • https://uploads.strikinglycdn.com/files/d21265bb-fdc5-41b7-a554-cad4d1adbadb/gopro_hero4_silver_iphone_app.pdf
    • http://fawujuvuz.epizy.com/sharepoint_2013_templates_free_download.pdf
    • https://uploads.strikinglycdn.com/files/742c6370-c0e8-4227-a2b3-3d2f0fea2ccc/25110075189.pdf
    • https://316b94d8-f1eb-4552-9621-e6dada6029ed.filesusr.com/ugd/4b675a_bd680c512485454fa052a43f07e63e9f.pdf?index=true
    • https://uploads.strikinglycdn.com/files/31e51b7e-a2d8-4a27-bc14-33e08fb83475/bosch_axxis_condensation_dryer_not_drying.pdf
    • https://77bc4ea4-de20-41c0-a463-a5315db628d9.filesusr.com/ugd/2c69e3_0265fa3b48cd42e18497c0f074ad932a.pdf?index=true
    • https://2a082fd4-e93f-4b8e-9e59-408fa046b31c.filesusr.com/ugd/e334dd_5a69fa15c4c443f18cc372d94cc12bf9.pdf?index=true
    • https://849cba27-c1c2-4801-a47f-514a08c45c3c.filesusr.com/ugd/7f7a2c_16b0a3562c0a4e2aac0216e9c764af61.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/