PDF static analysis report

Static analysis result for SHA-256 23fa94cf97bf9889…

SUSPICIOUS

PDF

146.6 KB Created: 2020-03-06 16:06:40 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6) First seen: 2020-09-24
MD5: 6906e3a113b5a88e2b8405b109c6c5a8 SHA-1: af82c0caf0deb7413c4142186a62607f28807159 SHA-256: 23fa94cf97bf9889ee2b69c3fa63df40d6570325652f05fa7686a7f4a6a263b8
44 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9986

Heuristics 4

  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bartolomeilaw.com/uploads/1/3/0/4/130483804/130483804.html#childhood+and+adolescence+voyages+in+development PDF link annotation
    • http://scalabilityvector.com/uploads/1/3/0/7/130775751/7604270.pdfIn PDF document text
    • http://shanisofficepreview.com/uploads/1/3/0/8/130814416/dusiliramobewerupi.pdfIn PDF document text
    • http://sweetideasandcompany.com/uploads/1/3/0/7/130740441/zopitojozen.pdfIn PDF document text
    • http://www.llanolionsclub.com/uploads/1/3/0/7/130776582/sozobifesumabutu.pdfIn PDF document text
    • http://unclejs.net/uploads/1/3/0/3/130379625/mogifusidutita.pdfIn PDF document text
    • http://reallytees.com/uploads/1/3/0/4/130491752/wejamowamu.pdfIn PDF document text
    • http://www.chapter6.americansingercanary.com/uploads/1/3/0/7/130740053/wavagifozanid_nitawev.pdfIn PDF document text
    • http://shotcomposer.com/uploads/1/3/0/2/130289651/3406762.pdfIn PDF document text
    • http://cordialcuffs.com/uploads/1/3/0/9/130969249/3457300.pdfIn PDF document text
    • http://krugmanwasright.com/uploads/1/3/0/6/130604254/9a6e3903cb96.pdfIn PDF document text
    • http://importedmakeup.net/uploads/1/3/0/8/130874516/zogovusaxezon.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000211d7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x211D7 8412 bytes
SHA-256: 01a67feef08cab3961e60a0163ad30400939e0330c0b892801311ce9a7530152
font_01_sfnt_off00023209.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x23209 2644 bytes
SHA-256: 84c8fc2357b131a6e7f9b951755245f9c194b96812ad5f3a41881e75f1419688