Malicious PDF / .VIR — malware analysis report

Static analysis result for SHA-256 26a905490db481e5…

MALICIOUS

PDF / .VIR

288.2 KB Created: 2024-02-27 11:25:59 Authoring application: SWFTools First seen: 2024-06-13
MD5: 0dc1e0901817abc65f45ba9468429c9a SHA-1: c23416a61881af4a772ed0845748ea39591fee92 SHA-256: 26a905490db481e5e960efbbf558d5db79fbee3b221afdef3c62267af50ac9d2
176 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9769

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.setofwatches.com/inc/goto.php?brand=Adriatica&url=https://assets.website-files.com/65f00856e35eedcbc9cc7299/662d1848e3da919f187051c1_zogavavanojidepop.pdf In PDF document text
    • https://tkbrollydemolition.com/?wptouch_switch=desktop&redirect=https://uploads-ssl.webflow.com/65dc8f6b008098122e440156/662d1044cf62638e9954fe11_28389897220.pdfIn PDF document text
    • http://mbdou73-rostov.ru/bitrix/click.php?anything=here&goto=https://uploads-ssl.webflow.com/65e889007261602dcdc2b8bb/662d2634b09babfb88ffc1ee_42460654066.pdfIn PDF document text
    • https://www.pharmacum.eu/akce.php?url=https://my.gadsdenstate.edu/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://joxuzi.sharynideas.com/f/41504634In PDF document text
    • https://www.adirondackvacations.net/sendoffsite.asp?url=https://uploads-ssl.webflow.com/65fff858c835756ac2e62b49/662d1fceb09babfb88fa5b5d_9280631239.pdf&image=https://www.lakegeorge.com/CommonImages/Banners/346.jpgIn PDF document text
    • http://www.image2d.com/fotografen.php?action=mdlInfo_link&url=https://www.ohiotech.edu/sites/all/modules/fckeditor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://fefanabafupok.theplazahotelbalanga.com/f/18765In PDF document text
    • http://circusfans.org/redirect.php?link_id=313&link_URL=https://uploads-ssl.webflow.com/660014a8120ce91830bf5e0c/662d156a72a9d6dd779c7a0d_54518012625.pdfIn PDF document text
    • https://hotteenpussy.net/amp/kdar.cgi?nnfd=1&s=65&u=https://uploads-ssl.webflow.com/65f00a8cdb518103ca160df5/662d19a9acb23c106e35f8f7_kitupabozop.pdfIn PDF document text
    • http://www.kafjord.kommune.no/search/1881.php/https://my.curry.edu/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://vizagibukizeve.thiranmanamalai.com/f/42329369In PDF document text
    • https://travel.care/bitrix/redirect.php?goto=https://lawnetportal.law.columbia.edu/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://tiwonuninex.sharynideas.com/f/508270718In PDF document text
    • https://www.novamarinsurance.com.mx/outbound?u=https://my.gadsdenstate.edu/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://ligudewodevese.mytickethomeband.com/f/45558In PDF document text
    • https://rumabunodix.cafij.co.za/97098617179945913849333442?tubevimilupurawetudomojutadojexexitipomozevoragimalevitinazerufufepukunimerejivalufo=zegupadurulivirukevisufejogatamoxawibonesazikubusujetalemekovoxivewitilomibedexigagolelivusiseroraminiwemigujipetenavasikagelulinoralatorezopojobigojikuremefefejotasobubelefilavabetifevokajumetaxivenozo&utm_kwd=construction+org+chart&disesoxebovusokabunupesevulaviwomipevolawimofejubotamumumubaruwasiverozowobanezemisebosoruxu=piwunawupolovaguzemanorizidotexafowunuzesufexodolegegiziwozodokazutupaselerafubujusomusevenikozarugafenuvajenemovefIn PDF document text
    • https://hdpornvideos.cc/xxx.php?link=video&p=100&u=https://uploads-ssl.webflow.com/65ffffe04e83ddea530c8b46/662d1afd39d25f6f2d036c7d_renaxubujeropuz.pdfIn PDF document text
    • https://rumabunodix.cafij.co.za/97098617179945913849333442?tubevimilupurawetudomojutadojexexitipomozevoragimalevitinazerufufepukunimerejivalufo=zegupadurulivirukevisufejogatamoxawibonesazikubusujetalemekovoxivewitilomibedexigagolelivusiseroraminiwemigujipetenavasikagelulinoralatorezopojobigojikuremePDF link annotation
    • https://rumabunodix.cafij.co.za/97098617179945913849333442?tubevimilupurawetudomojutadojexexitipomozevoragimalevitinazerufufepukunimerejivalufo=zegupadurulivirukevisufejogatamoxawibonesazikubusujetalemekovoxivewitilomibedexigagolelivusiseroraminiwemigujipetenavasikagelulinoralatorezopojobigojikuremefefejotasobubelefilavabetifevokajumetaxivenozo&utm_kwd=construction+org+chart&disesoxebovusokabunupesevulaviwomipevolawimofejubotamumumubaruwasiverozowobanezemisebosoruxu=piwunawupolovaguzemanorizidotPDF link annotation
    • https://www.routard.com/iclic.php?tl_id=437&part_id=1113&contenu_id=181&url=https://info.accs.edu/cfide/scripts/ajax/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://sabikufevob.club-directory.com/f/67983In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off00043025.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off00043025.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00043025.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x43025 12040 bytes
SHA-256: 0ac52ecb3a0bf137319526ea424236fa2f70c3ddc907cbcf06b8eb1715a8c9da
font_01_sfnt_off00044cda.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x44CDA 14808 bytes
SHA-256: 4828a52c0b44c78b8331ff873556e566009b13dc25f1c5b3e5e7ac47baef9ec6