PDF static analysis report

Static analysis result for SHA-256 529ee64a625db6ed…

SUSPICIOUS

PDF

39.8 KB Created: 2020-04-11 05:11:30 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6) First seen: 2020-09-24
MD5: 14df4d545070ba38f1b7d99cc6f1470f SHA-1: 0cece8d26219f815d6293960cc1d933381990b59 SHA-256: 529ee64a625db6ed9565f6a20952853740de5497267fe4f1f9aeb954a40929ad
36 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by an ML classifier as malicious. It contains multiple embedded URLs, one of which is directly referenced in the document body text. The primary malicious URL is http://moodlabnewlife.nl/uploads/1/3/0/6/130605166/130605166.html#a+car+is+driven+225+km+west, suggesting a lure to a potentially malicious webpage. No scripts were extracted, limiting further analysis of the payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9879

Heuristics 3

  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://moodlabnewlife.nl/uploads/1/3/0/6/130605166/130605166.html#a+car+is+driven+225+km+west PDF link annotation
    • http://orthodoxmalta.org/uploads/1/3/0/8/130814754/butotew.pdfIn PDF document text
    • http://www.schantzproduce.com/uploads/1/3/0/5/130588617/jidofuzamul.pdfIn PDF document text
    • http://corustest.devsite-1.com/uploads/1/3/0/2/130291589/rarezinijokij-zagar-vopawijezalob.pdfIn PDF document text
    • http://yogamamacb.com/uploads/1/3/0/6/130639115/saxata.pdfIn PDF document text
    • http://liveholi.org/uploads/1/3/0/4/130478648/rovetonamim.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005b3c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5B3C 9040 bytes
SHA-256: 137ff27edfc8279702aba6618884d618fd8aa3607d3996bb9816539920a8d323
font_01_sfnt_off00007df9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7DF9 16208 bytes
SHA-256: 5f95318943fcfbd77322bbb5cad315370152876080c91ba93f69ac7a8b13a41a