Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcf343c8cd7cfa4e…

MALICIOUS

PDF

83.1 KB Created: 2021-03-23 01:02:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 11eac1dcdc0fd7ad2accf0511953580b SHA-1: d853e3d54d1a5bc4706b4709ec78ffbe7b73fc6f SHA-256: fcf343c8cd7cfa4e700c5ca41175ee0e1518d5c40b627f484bbd0982d12583ab
66 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 6

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • ClamAV scan did not complete info CLAMAV_SCAN_INCOMPLETE
    ClamAV scan on this file did not complete (ClamAV error (exit 2)); the verdict reflects only static heuristics. The result is not cached so a later submission will retry the scan.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=husky+5000+watt+generator+parts+list
    • http://juwupexutaval.mywebcommunity.org/84040576531.pdf
    • https://cdn-cms.f-static.net/uploads/4423137/normal_6038e25c0a12d.pdf
    • https://dozunetad.weebly.com/uploads/1/3/4/4/134472758/9001342.pdf
    • https://gosopitodemeku.weebly.com/uploads/1/3/4/8/134874694/pidowamawawugoralata.pdf
    • http://fafesixokegigi.getenjoyment.net/blockchain_in_capital_markets.pdf
    • https://cdn-cms.f-static.net/uploads/4370987/normal_5fd12efbe59f2.pdf
    • http://nemosixumeki.mypressonline.com/musicoterapia_e_autismo_livro.pdf
    • https://fafenerukore.weebly.com/uploads/1/3/1/3/131398145/xesenogeva.pdf
    • https://jenejipita.weebly.com/uploads/1/3/4/4/134473981/sudozenapezatu.pdf
    • http://fisuruwibowin.66ghz.com/enzyme_amylase_lab_report.pdf
    • https://a21f0d7d-5fe0-4a99-a381-3b18266e0880.filesusr.com/ugd/6c313a_f94e2bec458448c398e4b87584b06fb2.pdf?index=true
    • https://f1e11ea9-a931-46ad-af30-391325c877dd.filesusr.com/ugd/423518_43077677d04f40bc9b90606e4cbfd598.pdf?index=true
    • https://uploads.strikinglycdn.com/files/37949cab-7fb9-4814-ba6c-a201b912ca0c/14099335158.pdf
    • https://c5c27394-2042-4749-9b39-d1c24dcbd9f0.filesusr.com/ugd/e9b987_a653d87c0f684082a698e27823a47355.pdf?index=true
    • https://uploads.strikinglycdn.com/files/37a1592a-a92e-42ce-a8b8-48af969f0138/does_the_gre_provide_formulas.pdf
    • https://90ff81fc-98d9-4e53-96a3-aaa5c1c2042e.filesusr.com/ugd/bb5aff_11a47249210a46c78c177bd2f6fbf743.pdf?index=true
    • http://muzudamufuvase.rf.gd/specialized_team_bike_computer_manual.pdf
    • http://jujobope.atwebpages.com/vutidoluzesifozaf.pdf
    • https://uploads.strikinglycdn.com/files/fb5d864f-5267-427d-a239-129b03c4addd/what_are_kitchen_trends_for_2020.pdf
    • https://uploads.strikinglycdn.com/files/b1999b90-d33f-447d-8208-285f76740e68/newuzokekupavop.pdf
    • http://natukifuza.atwebpages.com/yoga_asanas_and_their_benefits_in_tamil.pdf
    • https://efa91360-7c21-416c-9d60-3189e0beb381.filesusr.com/ugd/42ffc7_6b3ae9ad04ea4529aaff0006399ae872.pdf?index=true
    • https://uploads.strikinglycdn.com/files/816a70da-3f13-4945-9b77-77901216bf06/cuisinart_smartpower_duet_blender_food_processor_parts.pdf
    • http://fomabobas.epizy.com/10835638502.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/