PDF static analysis report

Static analysis result for SHA-256 26a4bf6f1e05ad2a…

SUSPICIOUS

PDF

50.6 KB Created: 2020-11-06 21:47:10 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-02
MD5: a90ef50abd11b3485ef624b4018b40cf SHA-1: 2c8c6f92ecb2fa17c411d5b2f0ef43a4593eafba SHA-256: 26a4bf6f1e05ad2a9909be622adc1e1538026145e115a41cd615ae4af7cf4790
34 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as suspicious by an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 2

  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffe.ru/aws?keyword=focus+on+forms+focus+on+meaning PDF link annotation
    • https://nibawomufexax.weebly.com/uploads/1/3/4/3/134371272/69643c481e3188d.pdfIn PDF document text
    • https://gonoloxezejuje.weebly.com/uploads/1/3/1/4/131410007/selez_roronumubazep_lanalubofow.pdfIn PDF document text
    • https://zubosevofugojat.weebly.com/uploads/1/3/4/3/134307347/1c2ba77a5e82652.pdfIn PDF document text
    • https://dufejubodumafeb.weebly.com/uploads/1/3/4/4/134444341/midipe.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c879e44b-f4a1-4aa5-997c-872deeec580e/refopebepojopaded.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2c32b5ef-42fd-4316-af7d-f89f3161b739/adobe_acrobat_pro_cracked_reddit.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fccc2d3e-a12f-4492-beec-3df9d2a10867/dnd_5e_spider_climb.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0b4fd7a3-2ac7-4f0a-b6e6-99e5cb57affe/dawuwikivuvavugipefan.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aae35475-df4e-4315-be97-2b9dbce6e0c7/4715012289.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2403aabb-1252-4739-b25a-46b746652d46/52631281738.pdfIn PDF document text
    • https://tuxabavijig.files.wordpress.com/2020/11/37940387668.pdfIn PDF document text
    • https://rezekine.files.wordpress.com/2020/11/tatojesanawav.pdfIn PDF document text