PDF static analysis report

Static analysis result for SHA-256 728c9f135d64a24f…

SUSPICIOUS

PDF

300.4 KB Created: 2021-08-05 22:05:40 +02:00 Authoring application: eostterre (via PDF Master 1.0.1) First seen: 2024-07-29
MD5: e608073de7ad83eea2936df9d543c156 SHA-1: 6d0db2dab5060e5f02ef4b38e93a5aa5010f777e SHA-256: 728c9f135d64a24f89f11e62e95b64f64826a2206c3d72580db9685f748c015b
29 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains multiple embedded URLs, with one specifically identified as part of a disposable redirector campaign. The document body text also lists various titles and URLs, suggesting a phishing or content-luring attempt. The primary URL, https://tiurll.com/21cs5v, is a strong indicator of malicious intent, likely leading to a phishing page or malware download. No scripts were extracted, but the presence of external links and the heuristic firings suggest an attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier clean score 0.0599

Heuristics 3

  • PDF links to disposable redirector campaign host medium PDF_DISPOSABLE_REDIRECTOR_CAMPAIGN
    PDF's outbound link points to a throwaway redirector domain that recurs as the sole redirect across a large family of otherwise unrelated spam PDFs (movie-piracy, affiliate, and viral-link lures). These domains appear on no reputable list and exist only to funnel openers into malvertising / scam / download chains.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://tiurll.com/21cs5v PDF link annotation
    • https://nervous-feynman-c1fc24.netlify.app/Biometrical-Techniques-In-Plant-Breeding-Pdf-DownloadIn PDF document text
    • https://nifty-thompson-4c94b8.netlify.app/http-ramonlbaezcomIn PDF document text
    • https://happy-albattani-65df83.netlify.app/ghajini-tamil-full-hd-movie-free-12In PDF document text
    • https://tilrahale.weebly.com/sexy-glamour-urdu-kahani-series-published-from-karachi.htmlIn PDF document text
    • https://forriburkli.weebly.com/federal-carryover-worksheet-total-withheld-pmts.htmlIn PDF document text
    • https://hungry-archimedes-0d05f8.netlify.app/Programming-Code-Wallpaper-posted-by-John-TremblayIn PDF document text
    • https://www.apokoronews.gr/advert/programming_in_ansi_c_by_balaguruswamy_4th_edition_pdf/In PDF document text
    • https://competent-poitras-9db75b.netlify.app/The-Walking-Dead-Zombie-Wallpaper-posted-by-Sarah-JohnsonIn PDF document text
    • http://teszt.albainfo.hu/advert/watch-rey-rey-telugu-movie-online/In PDF document text
    • https://uploads.strikinglycdn.com/files/6ffc8531-df9f-415d-8633-2ffc8345f7c8/Imagenes-De-Naomi-Scott-Desnuda.pdfIn PDF document text
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00000a8d.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xA8D 120140 bytes
SHA-256: a217f12862e0ff75203bdd4136ca0d68471050be46bb09aed5306898926ffdd4
font_01_sfnt_off0000b870.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB870 76772 bytes
SHA-256: 07ce6fea3c98bf59133021be55ce9147f9c26365efe580a2a4f82130ca697f54