Malicious PDF / .VIR — malware analysis report

Static analysis result for SHA-256 397614cf90a829bf…

MALICIOUS

PDF / .VIR

437.7 KB Created: 2023-08-27 19:23:57 Authoring application: Soda PDF First seen: 2024-04-14
MD5: 3a82b924551a2da55f547e2f397cf14b SHA-1: e63fba1028e32bad8a6084ef1c2321764fc38571 SHA-256: 397614cf90a829bf0df0f7e0cf547614a4ddfddc996736c34e3d8d321149cdd7
156 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.8903

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Viral-video clickbait PDF links to suspicious host critical SE_VIRAL_VIDEO_CLICKBAIT_LINK
    Document uses viral/leaked-video lure text and links to a suspicious disposable-looking web host. This is a clickbait/traffic-scam carrier shape rather than a benign PDF link.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://voyage-en-ecosse-avec-guide.xijugupel.sbs/korolujarukivu.pdf In PDF document text
    • https://massachusetts-math-standards.zobenot.sbs/513328397.pdfIn PDF document text
    • https://creando-tu-propia-riqueza-pdf.lancsports.com/xewosoxitotepomoxi.pdfIn PDF document text
    • https://adservice.google.co.zm/ddm/clk/466651624;272226156;i;;%3F//img1.wsimg.com/blobby/go/9b6ed793-452c-4f8f-8f80-6847f4d114d7/downloads/69727989842.pdfIn PDF document text
    • https://fawoz.synolo.co.za/61638634188469069?jobabefivuforubevatazolozebedisiragepuvojiniwezifewogitegel=futazatijupedevelekusawopavaxupafutizowobebavubumumeriduverofefawujanadenizomowotozetizilatujaduxekibaxuxepunujupuzegetomegonapelavolofubasisozeziridapijisevejodakikokupupimugokejakiberixejogavofoxenorabubuke&utm_kwd=audio+format+converter+apk&minunexinuvixafixofinaniwotivegamuvifovabikivokolujozekaxubizukolozuguferewijesijizud=wurogabaxeferapedowesagakomujurogulemesigejigejepenexelodebutexevutimupibudigividezorezuzozivozezuzujibosuzamojimitaluputivowivomabumomebIn PDF document text
    • https://fawoz.synolo.co.za/61638634188469069?jobabefivuforubevatazolozebedisiragepuvojiniwezifewogitegel=futazatijupedevelekusawopavaxupafutizowobebavubumumeriduverofefawujanadenizomowotozetizilatujaduxekibaxuxepunujupuzegetomegonapelavolofubasisozeziridapijisevejodakikokupupimugokejakiberixejogavofoxenorabubuke&utm_kwd=audio+format+converter+apk&minunexinuvixafixofinaniwotivegamuvifovabikivokolujozekaxubizukolozuguferewijesijizud=wurogabaxeferapedowesagakomujurogulemesigejigejepenexelodebutexevPDF link annotation
    • https://adservice.google.tl/ddm/clk/426382440;228185261;d;;%3F//img1.wsimg.com/blobby/go/317c70d2-fa4b-4e76-a183-b360102e2ab3/downloads/wusuwegu.pdfIn PDF document text
    • https://img1.wsimg.com/blobby/go/ef68f5bf-1c9e-4947-a4bc-478dc938b22c/downloads/7367048524.pdfIn PDF document text
    • https://adservice.google.tn/ddm/clk/408533097;208818505;l;;%3F//img1.wsimg.com/blobby/go/b5e9389c-d1de-49a0-a4a3-14325dd38d33/downloads/pevofulabubabumudup.pdfIn PDF document text
    • https://adservice.google.to/ddm/clk/295204063;122181591;w;;%3F//img1.wsimg.com/blobby/go/9c6cbe7f-76d2-4aee-a849-f537de278d42/downloads/72342444144.pdfIn PDF document text
    • https://img1.wsimg.com/blobby/go/5e849e0b-4662-48b9-bad1-95a56107c4c2/downloads/journal_entry_template.pdfIn PDF document text
    • https://adservice.google.com.ua/ddm/clk/478229754;284365575;c;;%3F//pexitob.letopudo.online/nemeg.pdfIn PDF document text
    • https://img1.wsimg.com/blobby/go/3af0602e-e6b8-430e-86d1-567d4658c658/downloads/alphabet_letters_with_pictures_worksheets.pdfIn PDF document text
    • https://img1.wsimg.com/blobby/go/a435afa7-bc93-481f-8a35-ce503cc8a972/downloads/webosen.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0006821f.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0006821f.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0006821f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6821F 12032 bytes
SHA-256: df8905468a55011b7bf8a7c601cd3a43f2cff6bf0363e32c6f99221c19f0138a
font_01_sfnt_off00069ee6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x69EE6 16180 bytes
SHA-256: a3d6a755d234e778d0ca041c21d47307541b76f202ab487d2f2106813cf519b2