PDF static analysis report

Static analysis result for SHA-256 320dfa7532640d6d…

SUSPICIOUS

PDF

70.5 KB Created: 2021-06-06 08:04:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-25
MD5: 861da5a1b9da4fe9b520fbe23489d5db SHA-1: 52f857074d5048a64589c0345443193fa9d646ad SHA-256: 320dfa7532640d6d51d7bea33742e4e6d48a159dace3d2c8491b3cd1cb1233eb
34 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as suspicious by an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7937

Heuristics 2

  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://irlanc.ru/pbw?utm_term=how+sugar+changed+the+world+article PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4374376/normal_5ff5c1b7a9cd1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4406775/normal_6068fb1633825.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4380411/normal_5fe8f820a22d5.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4385427/normal_5fc5cba411735.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4406806/normal_60473bb04068b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4445739/normal_601d93f7457db.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4384839/normal_5ffcf7429f2b6.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4464735/normal_6037f62b87810.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4456398/normal_60691140151e3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4463306/normal_60267b5ee144a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4483586/normal_601b02e2a71a5.pdfIn PDF document text
    • https://static.s123-cdn-static-d.com/uploads/4415944/normal_60b04a0d515f4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4470553/normal_605799536ae17.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4456376/normal_60bb74e758cc9.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391621/normal_601006422fa02.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/aa30d73c-2a00-4f20-8b32-1fe6b81fa10b/zero_belly_diet_book_free_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a11333d2-3f63-4dee-b638-b0982cfe5eaf/microsoft_sql_server_interview_guide.pdfIn PDF document text
    • http://luwivaj.pbworks.com/w/file/fetch/144487242/pusadidobudulivobajetesaz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0a8f343c-895d-446c-bab4-8df727edfeda/last_of_the_mohicans_1936_filming_locations.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/23907133-1fbe-4dc1-a8ad-67a19ef7015c/adding_mixed_fractions_calculator_soup.pdfIn PDF document text
    • http://gupiguna.pbworks.com/f/gta_iv_offline_activation_unlock-code_serial.pdfIn PDF document text
    • http://nusuwoxub.pbworks.com/f/41787998606.pdfIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed2a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xED2A 5252 bytes
SHA-256: 5e70374d5699c62d8abe5325b12fe4854a5a910b350322dc91158fa2a67a8ac7