Malicious PDF / .VIR — malware analysis report

Static analysis result for SHA-256 7c72623be58fcd9a…

MALICIOUS

PDF / .VIR

2.11 MB Created: 2008-02-07 13:30:02 +02:00 Authoring application: pdfFactory Pro www.pdffactory.com (via pdfFactory Pro 2.27 (Windows 2000 Professional Russian)) First seen: 2024-04-16
MD5: 76ec9018e406997897d169a7ce158e60 SHA-1: b8c3245488eacbbb2d369df280307d84b697b8bd SHA-256: 7c72623be58fcd9ad0a4ed4287be41f2ef488ff0d6652950a37c131de07a679b
92 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0009

Heuristics 5

  • Travel-support phone-number stuffing scam critical SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTH
    A PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
  • PDF static-analysis soft budget exhausted low SCAN_INCOMPLETE
    The bounded PDF scanner skipped late sub-format walkers after the configured per-file soft deadline. Earlier findings remain valid.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.pdffactory.com PDF link annotation
🗂 Part of campaign: pdffactory.com 18 samples