Malicious PDF / .VIR — malware analysis report

Static analysis result for SHA-256 9ced0150e73fdf52…

MALICIOUS

PDF / .VIR

324.1 KB Created: 2023-09-12 05:08:25 Authoring application: Poppler-utils First seen: 2024-09-20
MD5: d478ef854b3fe325419e3cec1badd6e6 SHA-1: 2c7528b20a8d6c96880cddaf7dc42f487f8850ca SHA-256: 9ced0150e73fdf52e9f13cf704d7ce2b6a834c650492f88e4d1bc8d8b2e7e100
76 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.8791

Heuristics 4

  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zeloxova.akgrafik.com/kivosibozuket.pdf PDF link annotation
    • https://fasej.tridentms.com/54525720456.pdfIn PDF document text
    • https://gijeba.yaguecf.com/34286984009.pdfIn PDF document text
    • https://sanoda.pianobusters.com/26828995290.pdfIn PDF document text
    • https://zakoza.freedomweekend.info/fuvupabu.pdfIn PDF document text
    • https://kekim.mctreadiness.com/jogebekevuxijutasurut.pdfIn PDF document text
    • https://lodis.brittanygroundhouse.com/wofezudeditido.pdfIn PDF document text
    • https://rifefijop.era-insurance.com/voromowukotatewitu.pdfIn PDF document text
    • https://figiza.mctreadiness.com/82188867517.pdfIn PDF document text
    • https://vokutita.mebel-rastem.com/52070608477.pdfIn PDF document text
    • https://tesaxubuku.lancsports.com/2273559770.pdfIn PDF document text
    • https://sonizuro.yaguecf.com/49995833914.pdfIn PDF document text
    • https://uploads-ssl.webflow.com/64f1a4a54d3c9690e94c1408/6547eab2d991bbc9046152b2_19566571390.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0004bb4d.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0004bb4d.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0004bb4d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4BB4D 11484 bytes
SHA-256: 30f37ce76404ed473cfd85d402a9d78a26cdbec5cb3fddeeda7dfb46272457b4
font_01_sfnt_off0004d646.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4D646 16688 bytes
SHA-256: 0bf8a345342a82149c2a76957465b3db00c6a4cbdcabe6af538ee951d51fd93d