Malicious PDF / .VIR — malware analysis report

Static analysis result for SHA-256 b94b1c524ff26117…

MALICIOUS

PDF / .VIR

19.6 KB First seen: 2024-12-24
MD5: 528465465c0e2504b5b292591aee6b7e SHA-1: 16d5b808ed55e40282ee3f98a939fc33efbc2a6d SHA-256: b94b1c524ff26117cea50bc8de4ae626bb22f5838506f8c65bc40d7f0d5bf468
74 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0023

Heuristics 4

  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • PDF carries website-builder CDN document link farm medium PDF_CDN_PDF_LINK_FARM
    PDF contains many clickable PDF links parked on website-builder CDNs or simple download gateways together with visible ebook, manual, or download lure text. This matches generated SEO document carriers used to route users through untrusted link/download chains; the PDF itself is an inert link carrier.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kab.litd.icu/dls.php?q=Cinterion+Mc55i+Manual PDF link annotation
    • https://cdn-cms.f-static.net/uploads/5250748/normal_60afd14e395d8.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5250831/normal_60afdb0d50918.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5250891/normal_60afdb5bb1c43.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5250832/normal_60afdd3cc024d.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5250661/normal_60afc96cd9dc4.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5250748/normal_60afd653e4625.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5250832/normal_60afd2e0c65e2.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5250884/normal_60afdb96b2400.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5256215/normal_60b2825c522b4.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5256215/normal_60b28248cf406.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5256215/normal_60b2826d70084.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5256215/normal_60b2827db6f17.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5256215/normal_60b282d06a494.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5256215/normal_60b2830135581.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5256215/normal_60b282e0ef210.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5256215/normal_60b282f08f181.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5256215/normal_60b282c00b28d.pdfIn extracted file (objstm_0039_00.bin)
    • https://cdn-cms.f-static.net/uploads/5256215/normal_60b282ae6cbc5.pdfIn extracted file (objstm_0039_00.bin)
🗂 Part of campaign: f-static.net 38 samples

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objstm_0039_00.bin pdf-objstm-decoded PDF /ObjStm 39 0 obj (inflated) 6174 bytes
SHA-256: 2ec4d5f2bf5f2820418ef73d0dccbd494b9d1178685e0bbbe0e75561f3e347ce