Malicious PDF / .VIR — malware analysis report

Static analysis result for SHA-256 c7dc8171ddeae6d8…

MALICIOUS

PDF / .VIR

654.3 KB Created: 2023-10-18 23:56:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2024-06-13
MD5: 8f8a029383ae9bda81992c39fc24c8fe SHA-1: cbc4e1e0e37c71640215a299c8b06c7b5b873d7f SHA-256: c7dc8171ddeae6d81da2f2810c61cedd9490e3bc5e671349b6e7752f7dff6648
136 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.5725

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://sebar.joopsoa.com/1006207789391214665630?tudexuvovuzemakanezamatulonirovopikojenaxozepomubugatime=takebekobavunaxemokuminitimuxeturapisovazimosilinedojaludikilatokafuzibagugerodepiraxunowaturagifesavosubigimeromuxuzatapepowumusetiferewixinowevikinulirirejupokidadeguwizarasutojodixigamezigufalojuxererin&keyword=gcse+biology+kerboodle+textbook+answers&zozijisoxotejalabumowejopiwogimozileturorexojizakedu=warunamimabefixuzifitufejadezemokilawowobegosipozokebunagigemozavukazojawopupixazarakuxarojedelabuvuteburab In PDF document text
    • https://sebar.joopsoa.com/1006207789391214665630?tudexuvovuzemakanezamatulonirovopikojenaxozepomubugatime=takebekobavunaxemokuminitimuxeturapisovazimosilinedojaludikilatokafuzibagugerodepiraxunowaturagifesavosubigimeromuxuzatapepowumusetiferewixinowevikinulirirejupokidadeguwizarasutojodixigamezigufalojuxererin&keyword=gcse+biology+kerboodle+textbook+answers&zozijisoxotejalabumowejopiwogimozileturorexojizakedu=warunamimabefixuzifitufejadezemokilawowobegosipozokebunagigemozavukazojawopupixazarakuxPDF link annotation
    • https://sebar.joopsoa.com/1006207789391214665630?tudexuvovuzemakanezamatulonirovopikojenaxozepomubugatime=takebekobavunaxemokuminitimuxeturapisovazimosilinedojaludikilatokafuzibagugerodepiraxunowaturagifesavosubigimeromuxuzatapepowumusetiferewixinowevikinulirirejupokidadeguwizarasutojodixigamezigufaPDF link annotation
    • https://img1.wsimg.com/blobby/go/c21f1d1d-54cf-4880-b5b7-84d8867f14e5/downloads/zipixebijemavafita.pdfIn PDF document text
    • https://uploads-ssl.webflow.com/64ee04a5599521d5f7f0d0cb/652de40828965971af08c8ea_dopoxenazamutobufewa.pdfIn PDF document text
    • https://img1.wsimg.com/blobby/go/e9a471a8-015e-460b-aab7-60accb720643/downloads/interchange_5th_edition_level_3b_student_book_free_download.pdfIn PDF document text
    • https://img1.wsimg.com/blobby/go/15dc1bec-22ea-4933-88d4-f56396e120d9/downloads/latozo.pdfIn PDF document text
    • https://img1.wsimg.com/blobby/go/9441f8ad-6e79-4d4a-9602-3585b1269b7e/downloads/plot_of_romeo_and_juliet_act_1.pdfIn PDF document text
    • https://uploads-ssl.webflow.com/64f1a1f8d4dab2b32b1716c5/652de33e9b1f890eaf0d9999_54080939862.pdfIn PDF document text
    • https://uploads-ssl.webflow.com/64ee0fa5fbdf140b3bcd53e8/652de6fd7dc20e0e375eb2b3_kitimovi.pdfIn PDF document text
    • https://uploads-ssl.webflow.com/64f852a7318057bf6eb8e1a1/652de3a9b648708ca6669800_polemopar.pdfIn PDF document text
    • https://img1.wsimg.com/blobby/go/850944a7-1e64-431d-a1b4-eaff90dad92e/downloads/33409115732.pdfIn PDF document text
    • https://img1.wsimg.com/blobby/go/f1560984-1ad6-42dd-8c0f-73844707e092/downloads/36136298820.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0009e840.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0009e840.bin)
🗂 Part of campaign: shared payload a02f67deb0 41 samples

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0009e840.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9E840 18744 bytes
SHA-256: eb9861e7e380f5aec2c4925be3d339cfc6619755eb2ce0c3f212608ab8d6674e
font_01_sfnt_off000a18cf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA18CF 8940 bytes
SHA-256: a02f67deb084b7ce8e02d7004994a9dd7e3132fe24919a42c6f0df6ed367c188