Malicious PDF / .VIR — malware analysis report

Static analysis result for SHA-256 f1ddba4edab2bc62…

MALICIOUS

PDF / .VIR

562.0 KB Created: 2024-01-30 06:34:22 Authoring application: LibreOffice First seen: 2024-05-27
MD5: 4d64fa1e58980863742bc3731eefa5b9 SHA-1: a2f7da1354be4ecc356a502f3928447619204722 SHA-256: f1ddba4edab2bc625a56e23eacc05879d636222528feb9dff4e788fb7293b590
216 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document contains multiple heuristics indicating malicious intent, including random and encoded URLs. One URL decodes to a recipient email address 'udsw@socialskills4you.com', suggesting a phishing or spam campaign. The ML classifier and ClamAV detection further support its malicious nature. The embedded URLs likely lead to further stages of infection or phishing content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8638

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • Clickable URL hides a base64-encoded recipient email high PDF_URL_ENCODED_RECIPIENT_EMAIL
    PDF has a clickable HTTP(S) action whose URL carries the recipient's email address base64- or URL-encoded in a query parameter or the #fragment, on generated/disposable web infrastructure or behind a URL-security / open-redirect wrapper. Encoding the recipient hides it from plain-text inspection and origin-side logs while the landing page decodes it client-side to pre-fill and track the credential form. A legitimate link does not obfuscate the recipient this way.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://rareanalsex.com/xxx.php?link=video-bookmark&skip_sell=true&url=https://jagwire.tamusa.edu/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://kubunusilujudos.supremainmobiliaria.com/f/318805147 In PDF document text
    • http://www.theconsultancygroup.nl/traffic.php?url=https://uploads-ssl.webflow.com/66000c4413d5a8d681cda800/662febbb9389eada345aed1e_vexixidi.pdfIn PDF document text
    • https://www.fertilizerdaily.ru/goto/https://my.canisius.edu/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://biwusupolob.salvaralbucardo.com/f/83353972In PDF document text
    • https://www.btceth2.com/go.php?gourl=https://uploads-ssl.webflow.com/65dcb1dcee0d5d0705e15ff0/662ff816b0ce234b3a532d8b_8872591168.pdf&id=1914In PDF document text
    • http://fermereve.ru/bitrix/redirect.php?goto=https://uploads-ssl.webflow.com/65f01c8167f3d7c7ea4807e2/662fec37f2b4da21106fe85d_tofamabanis.pdfIn PDF document text
    • https://prettysix.com/appredirect.php?link=https://portal3.samford.edu/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://lubuzubagujanid.salvaralbucardo.com/f/8938In PDF document text
    • https://a4foot.com/en/redirect?url=https://portal.wheatonma.edu/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://joxomokegof.salvaralbucardo.com/f/21573In PDF document text
    • http://pgire.it/redirect_click.aspx?id=921&url=https://mdphd.ouhsc.edu/cfide/scripts/ajax/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://zagel.gfxtoolkit.com/f/2375In PDF document text
    • https://newsletter.gewerbeverein.at/lm/lm.php?tk=VXJzdWxhCURlbGxhIFNjaGlhdmEtV2lua2xlcgkJdWRzd0Bzb2NpYWxza2lsbHM0eW91LmNvbQlIw6RydGVmYWxsLCBMaXF1aWRpdMOkdCwgU2NodXR6bWFza2VuIC0gQ29yb25hLUxldHRlciAzMS4zLjIwMjAJMzYzCU5ldWlna2VpdGVuCTM5MTAJY2xpY2sJeWVzCW5v&url=https://my.lcc.edu/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://xanavefe.thiranmanamalai.com/f/945896228In PDF document text
    • http://tapchiqptd.vn/advviewnumber.aspx?ID=174&URL=https://www.mondragon.edu/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://vexug.mytickethomeband.com/f/28635938In PDF document text
    • https://www.nylonwives.com/cgi-bin/a2/out.cgi?c=0&l=page_top_spo&u=https://connect.cuchicago.edu/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://jilod.skyangelus.com/f/28350756In PDF document text
    • http://ww.sdam-snimu.ru/redirect.php?url=https://uploads-ssl.webflow.com/65e86e9e111679c7ef08960a/662ff9d1e63103381dea970d_sibetediwoni.pdfIn PDF document text
    • https://www.otoriyose.net/cgi-bin/re.cgi?lid=f14as&url=https://portal.duq.edu/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://wufoseto.theplazahotelbalanga.com/f/45518188In PDF document text
    • https://printindustry.ru/goto/https://portal.uas.alaska.edu/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://dujebosiwogibov.supremainmobiliaria.com/f/61479In PDF document text
    • http://odbkaluga.ru/bitrix/redirect.php?event1=click_to_call&event2=&event3=&goto=https://assets.website-files.com/65e87f56e7f3910126edaacc/662febb6a8be825e0524a1e4_28678680262.pdfIn PDF document text
    • http://k1s.jp/callbook/cgi-bin/rank.cgi?mode=link&id=1104&url=https://assets.website-files.com/65fff858c835756ac2e62b49/662ff05845ab92d170d877bd_70757878455.pdfIn PDF document text
    • https://pochtipochta.ru/redirect?url=https://assets.website-files.com/65ffd7f697fdea31bc0146d2/662ff5bdee0b1c397e49f4d4_teredi.pdfIn PDF document text
    • https://medikapobinana.podar.co.za/45461805516463150140324532?febomaxokisatifepipaxopexopofewij=gevufakalaruvuliwurevetivazufubigonekavikeputivikizifebalinugusomotozubivewevuvitakemodifapirodinegirakugadirunatatewevusopalukovebativazemavikowizifivojowugedapulagefufizijixirisuvofuwaxesemikuwabile&utm_kwd=periodic+table+questions+and+answers+pdf&jogesaforesanebapafeximasezusalimatimiwetanigosugobomorunesepalofupapeson=kerojabaxixuzogujigebiresuvexogojexeganilitorasuwuturipodozogotipaferisiboxixekewuwexobijitegadixipavemowuvonexokeloxagasusepizazudokiwonanIn PDF document text
    • https://www.listasul.com/guia/registra_click.php?site=https://arhusynergy.umd.edu/sites/all/libraries/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://mijafe.theplazahotelbalanga.com/f/80402664&userid=0&objeto=INS&codguia=54&cli=2&codcli=18826&cto=In PDF document text
    • https://medikapobinana.podar.co.za/45461805516463150140324532?febomaxokisatifepipaxopexopofewij=gevufakalaruvuliwurevetivazufubigonekavikeputivikizifebalinugusomotozubivewevuvitakemodifapirodinegirakugadirunatatewevusopalukovebativazemavikowizifivojowugedapulagefufizijixirisuvofuwaxesemikuwabile&utmPDF link annotation
    • https://medikapobinana.podar.co.za/45461805516463150140324532?febomaxokisatifepipaxopexopofewij=gevufakalaruvuliwurevetivazufubigonekavikeputivikizifebalinugusomotozubivewevuvitakemodifapirodinegirakugadirunatatewevusopalukovebativazemavikowizifivojowugedapulagefufizijixirisuvofuwaxesemikuwabile&utm_kwd=periodic+table+questions+and+answers+pdf&jogesaforesanebapafeximasezusalimatimiwetanigosugobomorunesepalofupapeson=kerojabaxixuzogujigebiresuvexogojexeganilitorasuwuturipodozogotipaferisiboxixekePDF link annotation
    • http://ygelebart.free.fr/redir.php?link=https://chesapeakebay.umd.edu/sites/all/modules/fckeditor/fckeditor/editor/filemanager/browser/default/browser.html?Connector=https://nurub.salvaralbucardo.com/f/12612227In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off00086a1b.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off00086a1b.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00086a1b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x86A1B 13200 bytes
SHA-256: b796e80b0282c49e0b7958f5b8d69963485d4863f640e5e8913dc232937bbd47
font_01_sfnt_off00088a44.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x88A44 17292 bytes
SHA-256: a1afd35d03a01f56a79135f72c6a9a42496094f2e52ec70d6ace3dc7eefc7ccd