PDF static analysis report

Static analysis result for SHA-256 67a07ca3540be08a…

SUSPICIOUS

PDF

363.6 KB Created: 2017-09-22 22:36:16 +03:00 Authoring application: www.convertapi.com First seen: 2018-05-08
MD5: 2e7f985c570d1ab106f44406bd525151 SHA-1: ea736131e646109bef98be1383f4eef5886358da SHA-256: 67a07ca3540be08aa0577fd7aa2d050c6fb19ce37e7e3ef82a705697fc43dd7c
36 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF was flagged by an ML classifier as malicious and contains embedded URLs pointing to potentially malicious domains. The 'PDF_IMAGE_ONLY_LURE' heuristic indicates the document is designed to appear as an image, a common tactic to bypass content analysis and trick users into clicking links. While no scripts were explicitly extracted, the presence of external URIs and the ML classification suggest an intent to redirect the user to a malicious site for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8600

Heuristics 3

  • External URI info PDF_URI
    PDF contains an external URL action
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.frutiko.hr/indexxx.php PDF link annotation
    • http://bloombaptist.org/dec/news.htmlIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYouIn PDF document text
    • http://www.microsoft.com/typography/fonts/default.aspxIn PDF document text
    • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XIn PDF document text
    • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl0ZIn PDF document text
    • http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn PDF document text
    • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In PDF document text
    • http://www.microsoft.com/Typography/0In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00046fdf.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x46FDF 173484 bytes
SHA-256: f3bf9704ae1a1b01d6eaba8c4203245dfddd8957cdd25f52cca46afe823164ba