Malicious PDF / .VIR — malware analysis report

Static analysis result for SHA-256 b72984e0d0f172d9…

MALICIOUS

PDF / .VIR

220.9 KB Created: 2021-07-26 03:07:48 +02:00 Authoring application: rachahelm (via PDF Master 1.0.1) First seen: 2024-06-14
MD5: f9208cbfe83efbfa59e7328cb54984d3 SHA-1: 6ffc3231109ad7b79446eaebe568df3cfd4828ba SHA-256: b72984e0d0f172d905a7550db6ab8f321f1a6dfdc2eadb1d9e35c5065bd2c1aa
84 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0124

Heuristics 5

  • PDF links to disposable redirector campaign host medium PDF_DISPOSABLE_REDIRECTOR_CAMPAIGN
    PDF's outbound link points to a throwaway redirector domain that recurs as the sole redirect across a large family of otherwise unrelated spam PDFs (movie-piracy, affiliate, and viral-link lures). These domains appear on no reputable list and exist only to funnel openers into malvertising / scam / download chains.
  • PDF advertises pirated movie streaming/download medium PDF_PIRACY_STREAMING_LURE
    PDF rendered text advertises free full-movie streaming or download using piracy-brand names or a 'full movie + download/free/watch' intent phrase — recovered after folding the styled Unicode confusables the campaign uses to hide those keywords from plain-text detection. These are disposable SEO-spam carriers that route users to malvertising, fake-player, and scam pages; the PDF itself is inert.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bytlly.com/206ts2 PDF link annotation
    • https://bunowpayti.weebly.com/me-and-my-sister-now--then-girls-family-d06f9bd8c4c544ee9570870069c8-imgsrcru.htmlIn PDF document text
    • https://quiconnisi.weebly.com/mauren-fbimg1596738587776-imgsrcru.htmlIn PDF document text
    • http://doctorsonline.co.in/advert/live-northwestern-vs-nebraska-streaming-online-link-2/In PDF document text
    • https://creativeu.live/advert/solucionario-besterfield-control-de-la-calidad-rapidshare/In PDF document text
    • https://www.yourlocalcleaningservices.com/index.php/advert/ligo-na-u-lapit-na-me-book-pdf-download100/In PDF document text
    • https://trello.com/c/A9PEiuwo/546-download-full-movie-dragon-in-italian-topIn PDF document text
    • https://kit.co/schulimanan/cindy-cindy-becky-imgsrc-ru-free/cindy-cindy-beckyIn PDF document text
    • https://uploads.strikinglycdn.com/files/81035e2d-089e-430a-b772-c93efd3ed646/--2017--In-August-2017-DSCF6585-iMGSRCRU.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3358c418-293c-427c-b9ea-8fbe41d4b2b3/2016002-boys-in-speedo-and-other-clothes-201505-350-iMGSRCRU.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/252c03d6-b46d-4f8d-bc93-6457d7598ed5/Sara--young-girl-in-bikini-PICT1894-iMGSRCRU.pdfIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.iec.chIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00000ee1.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xEE1 120640 bytes
SHA-256: 69a21d75db3571b4c63ef0dd5d3f13c089ace34d6f6190e8118aff00e2264edb
icc_00_off0003349d.icc pdf-icc-profile PDF ICC profile at offset 0x3349D 3144 bytes
SHA-256: 3f6d674174f3804eb0dabdac90ae17486e898c5063a66f861c116ea033da8301
font_01_sfnt_off0000bde2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBDE2 76772 bytes
SHA-256: 07ce6fea3c98bf59133021be55ce9147f9c26365efe580a2a4f82130ca697f54