PDF static analysis report

Static analysis result for SHA-256 2a3259217547d354…

SUSPICIOUS

PDF

182.6 KB Created: 2020-03-30 16:47:37 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6) First seen: 2020-09-15
MD5: 0219e7ffff326b094a720ade7bbc48df SHA-1: 7cfd0bb2d214551a6827a4e08ab4a1df33ce376b SHA-256: 2a3259217547d354f10101bc81b746564c0527d7247c30fff814e03e3dd524c6
44 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The ML classifier strongly indicates maliciousness. The document body contains text suggesting urgency, such as 'account will be terminated' and 'action required within 24 hours', which is a common lure tactic. The PDF contains multiple embedded URLs, with the primary one being http://nwspecialtylumbermill.com/uploads/1/3/0/6/130605384/130605384.html#floureon+pocket+fetal+doppler, likely leading to a phishing or malware download page.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9955

Heuristics 4

  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://nwspecialtylumbermill.com/uploads/1/3/0/6/130605384/130605384.html#floureon+pocket+fetal+doppler PDF link annotation
    • http://timelessalpha.shop/uploads/1/3/0/5/130538866/b4f0d0.pdfIn PDF document text
    • http://lgbaonline.org/uploads/1/3/1/3/131384606/ximugowizatikewigev.pdfIn PDF document text
    • http://divinealliances.org/uploads/1/3/0/3/130313784/b04e17f49aa5.pdfIn PDF document text
    • http://augusta-flooring.com/uploads/1/3/0/5/130588710/1050473.pdfIn PDF document text
    • http://ohmsweetohmmn.com/uploads/1/3/0/5/130588246/501d529b3acac.pdfIn PDF document text
    • http://dematic-university.com/uploads/1/3/0/6/130621261/a4ec974e.pdfIn PDF document text
    • http://robertcvitkovic.com/uploads/1/3/0/2/130273842/753931.pdfIn PDF document text
    • http://misogi0001.com/uploads/1/3/0/9/130969435/porug.pdfIn PDF document text
    • http://rootgolfperformance.com/uploads/1/3/0/4/130483690/2904126.pdfIn PDF document text
    • http://i-nine.com/uploads/1/3/0/5/130590550/pofilasifexenuj_zaramuro_rogiwabenewal_zitemewepesamim.pdfIn PDF document text
    • http://ntro4k.com/uploads/1/3/0/5/130546024/6833909.pdfIn PDF document text
    • http://aaroncharlesg.com/uploads/1/3/0/4/130483074/c0afb.pdfIn PDF document text
    • http://designyoursalonandspasuccess.com/uploads/1/3/0/6/130621663/822542cae9b7a7.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text
    • http://www.adobe.com/).NotoIn PDF document text
    • http://www.google.com/get/noto/http://www.adobe.com/type/ThisIn PDF document text
    • http://scripts.sil.org/OFLNotoIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000277cc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x277CC 10520 bytes
SHA-256: 9528f38ec9144e4c8dbd17766bfaecaf90b8c36a05c8f9f0cac1462b4adfe2f2
font_01_sfnt_off00029ebd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x29EBD 2780 bytes
SHA-256: 1acd950b31dc6140a1115cd1643d9471fb9ab50ac1e109cb9ee0df24551d95c9
font_02_sfnt_off0002a863.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2A863 4176 bytes
SHA-256: 37e696e3b90e4f6c40450276623066bfb4958bac890a948cfa2b6adc1de7ae36
font_03_sfnt_off0002b592.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2B592 16168 bytes
SHA-256: 0437ae0a8c3b0d4d0bca19117c23f937da5e886acb635ecc2018453b05816554