Malicious PDF / .VIR — malware analysis report

Static analysis result for SHA-256 4f08daa61d981fb8…

MALICIOUS

PDF / .VIR

296.5 KB Created: 2023-06-14 17:26:31 Authoring application: Pdftk First seen: 2024-09-28
MD5: 0d8edb28a13f553234dfd71af40c70a3 SHA-1: f76146f5e21acf514dbdc1a898f27282ca9683b1 SHA-256: 4f08daa61d981fb867b48547aaca9ace08b2d4d703b3b765ca89b877d1a5609d
186 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0537

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • ClickFix social engineering attack high SE_CLICKFIX
    Document instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://metud.brittanygroundhouse.com/20877434299.pdf In PDF document text
    • https://vulokut.peykweb.com/66603383947.pdfIn PDF document text
    • https://rodewanux.mctreadiness.com/risezimezebiwu.pdfIn PDF document text
    • https://pifij.chaosdev.org/kosemiguvojuv.pdfIn PDF document text
    • https://dagosasa.peykweb.com/96046119492.pdfIn PDF document text
    • https://lamulogezijod.haviol.co.za/379073387639697183?vibujuximizefarebirevaxutuwipiwaduduzokinotajuwekudesolovilugo=wusorefexovikolapirejedulujemofovuvimapinabuvinezinurexutofamemumafirunosaxuvewozonaxexodafenesujukilokexofewexixajubumugazivufexuzinupakuwifixukojegebemadamaribafokatimopovawesetomaxumufebobajavexazibofek&utm_kwd=hp+printer+won%27t+print+from+internet&tikumepurevajakofejejixikuvukakuxeruwavubisulokixodupusakugedolusivazulotokoni=tinapogaselodudamelinibifisimosikitetaxaxelazipuvedadunevazosetopepilomoputexezifolitafabikevojezimarasojikijalazopowomededuwonoxanabikufIn PDF document text
    • https://lamulogezijod.haviol.co.za/379073387639697183?vibujuximizefarebirevaxutuwipiwaduduzokinotajuwekudesolovilugo=wusorefexovikolapirejedulujemofovuvimapinabuvinezinurexutofamemumafirunosaxuvewozonaxexodafenesujukilokexofewexixajubumugazivufexuzinupakuwifixukojegebemadamaribafokatimopovawesetomaxPDF link annotation
    • https://lamulogezijod.haviol.co.za/379073387639697183?vibujuximizefarebirevaxutuwipiwaduduzokinotajuwekudesolovilugo=wusorefexovikolapirejedulujemofovuvimapinabuvinezinurexutofamemumafirunosaxuvewozonaxexodafenesujukilokexofewexixajubumugazivufexuzinupakuwifixukojegebemadamaribafokatimopovawesetomaxumufebobajavexazibofek&utm_kwd=hp+printer+won%27t+print+from+internet&tikumepurevajakofejejixikuvukakuxeruwavubisulokixodupusakugedolusivazulotokoni=tinapogaselodudamelinibifisimosikitetaxaxelazipuvedPDF link annotation
    • http://wenq.org/In extracted file (font_00_sfnt_off00043beb.bin)
    • https://uploads-ssl.webflow.com/64eddd955cc39e56b0385d9a/6548a2ad7d76af5bc7aff9d4_liwasapikixawegevijidurip.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://nmr.mgh.harvard.edu/~fangq/In extracted file (font_00_sfnt_off00043beb.bin)
    • http://www.gnu.org/copyleft/gpl.htmlIn extracted file (font_00_sfnt_off00043beb.bin)
    • http://dejavu.sourceforge.netIn extracted file (font_01_sfnt_off00044605.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_01_sfnt_off00044605.bin)
🗂 Part of campaign: wenq.org 13 samples

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00043beb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x43BEB 3096 bytes
SHA-256: 8fc38416c2742673f47a9487c22d60e89192861cc0c999e641ee7ff6f06c706e
font_01_sfnt_off00044605.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x44605 10624 bytes
SHA-256: 440958c04751da6ec1fc199328df9ad1de90bef542cf83b95d7f824b8dca7ced
font_02_sfnt_off00045e35.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x45E35 17312 bytes
SHA-256: 713090fadf08a9e2799a5c89e2e63039f560a0473b94416e65e02ee62e11efe8
font_03_sfnt_off00048b89.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x48B89 952 bytes
SHA-256: 69008aeef9562507d70140c6eae623135a247217609a9d6c240bd6eea57126eb