Malicious PDF / .VIR — malware analysis report

Static analysis result for SHA-256 bd971b2bfc2f0c10…

MALICIOUS

PDF / .VIR

91.2 KB Created: 2021-12-10 19:57:39 +03:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2024-07-29
MD5: 2863d4d9c4f63eb5d0872d0ad3ee55c4 SHA-1: ed3ddcceba8851fcdbe2b83d3be1f9e9fbc97238 SHA-256: bd971b2bfc2f0c107dcf4ab86d351fd18651d273982c57f682e57e2c0a4783fa
107 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0333

Heuristics 6

  • Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LURE
    Document describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
  • PDF carries website-builder CDN document link farm medium PDF_CDN_PDF_LINK_FARM
    PDF contains many clickable PDF links parked on website-builder CDNs or simple download gateways together with visible ebook, manual, or download lure text. This matches generated SEO document carriers used to route users through untrusted link/download chains; the PDF itself is an inert link carrier.
  • PDF links to disposable redirector campaign host medium PDF_DISPOSABLE_REDIRECTOR_CAMPAIGN
    PDF's outbound link points to a throwaway redirector domain that recurs as the sole redirect across a large family of otherwise unrelated spam PDFs (movie-piracy, affiliate, and viral-link lures). These domains appear on no reputable list and exist only to funnel openers into malvertising / scam / download chains.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://getpdf.pw/book?res=weby&isbn=9781733490351&kwd=Exodus%20:%20The%20Exodus%20Revelation%20by%20Trey%20Smith PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4663792/normal_61b2078b7e73a.pdfIn PDF document text
    • https://static.s123-cdn-static-b.com/uploads/4660785/normal_61b152c911c9d.pdfIn PDF document text
    • https://files8.webydo.com/9589249/UploadedFiles/0E218EBD-669E-38D0-E89C-2C16690CDB50.pdfIn PDF document text
    • https://files8.webydo.com/9589191/UploadedFiles/16F16680-F33B-EE18-C24C-47603CAA7670.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4664440/normal_61b25f6840392.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/622d9775-e89b-4c8c-9f29-9dcd5666b9b2/bird-on-my-shoulder-a-memoir-517.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn extracted file (font_00_sfnt_off00010d44.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010d44.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10D44 21632 bytes
SHA-256: efbbdbfdecad15444f219ede67f124c4a65b8ac15cf40e1aa45805645c9085e6
font_01_sfnt_off00013f87.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13F87 19556 bytes
SHA-256: 8365cbe6708b1aa9e86d6c2348e8cb1ecb423ce919e0c2d105d94d34b57feaf6