Malicious PDF / .VIR — malware analysis report

Static analysis result for SHA-256 661384c7107be01a…

MALICIOUS

PDF / .VIR

303.5 KB Created: 2019-02-20 16:01:56 -05:00 Authoring application: Microsoft® Access® 2010 First seen: 2024-07-29
MD5: 4490b83bf424292a309c14b8b843cb44 SHA-1: a4a4b6ab480a0f12fcdadfe94099fbb6e899a4b8 SHA-256: 661384c7107be01aab8de53aea566a717e5f68b031978571b6fc5cafc425fce2
62 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0001

Heuristics 2

  • Travel-support phone-number stuffing scam critical SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYou In extracted file (stream_010_off0003412b.bin)
    • http://www.microsoft.com/typography/fonts/default.aspxIn extracted file (stream_010_off0003412b.bin)
    • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XIn extracted file (stream_010_off0003412b.bin)
    • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In extracted file (stream_010_off0003412b.bin)
    • http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0aIn extracted file (stream_010_off0003412b.bin)
    • http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0In extracted file (stream_010_off0003412b.bin)
    • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn extracted file (stream_010_off0003412b.bin)
    • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In extracted file (stream_010_off0003412b.bin)
    • http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^In extracted file (stream_010_off0003412b.bin)
    • http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��In extracted file (stream_010_off0003412b.bin)
    • http://www.microsoft.com/pkiops/docs/primarycps.htm0@In extracted file (stream_010_off0003412b.bin)
    • http://www.microsoft.com/TypographyIn extracted file (stream_010_off0003412b.bin)
    • https://www.verisign.com/repository/CPS��In extracted file (font_00_sfnt_off0001b7c4.bin)
    • https://www.verisign.comIn extracted file (font_00_sfnt_off0001b7c4.bin)
    • https://www.verisign.com/repository/verisignlogo.gif06In extracted file (font_00_sfnt_off0001b7c4.bin)
    • http://status.verisign.com/class1.crl0In extracted file (font_00_sfnt_off0001b7c4.bin)
    • http://www.microsoft.com/typographyIn extracted file (font_00_sfnt_off0001b7c4.bin)
    • http://crl.microsoft.com/pki/crl/products/CSPCA.crl0HIn extracted file (font_03_sfnt_off00048587.bin)
    • http://www.microsoft.com/pki/certs/CSPCA.crt0In extracted file (font_03_sfnt_off00048587.bin)
    • http://crl.microsoft.com/pki/crl/products/tspca.crl0HIn extracted file (font_03_sfnt_off00048587.bin)
    • http://www.microsoft.com/pki/certs/tspca.crt0In extracted file (font_03_sfnt_off00048587.bin)

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off0000656d.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x656D 304722 bytes
SHA-256: 1546bb558f8280fd49a26a5eb6440ae3367cccdc6500f76d65e31a0d707e140d
stream_010_off0003412b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3412B 177672 bytes
SHA-256: 817538cafe76a86bb8aec4ced0a93c240c17409eb5b3f0f98318f8a4b1a26f1a
font_00_sfnt_off0001b7c4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1B7C4 15100 bytes
SHA-256: 2c75817ffab8663b9529be9bb7316f0fb6e17059357254d2ed5fd0837d2ea884
font_01_sfnt_off0001dc43.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1DC43 187720 bytes
SHA-256: b6e578c0757bef231fbbf7c3cb2bbd8ffba676e182941e8abcdaaa854a6e1034
font_03_sfnt_off00048587.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x48587 39984 bytes
SHA-256: 42e7928f9e3c4084f6ec37d09cbef43c93b735dacadaac70c3772635c0edd2a4