PDF static analysis report

Static analysis result for SHA-256 827b3aeb8767e0cb…

CLEAN

PDF

461.1 KB Created: 2012-09-30 22:26:34 -04:00 Authoring application: Microsoft® Word 2010 First seen: 2017-03-23
MD5: e30e3b4bf8699e022e06365fb49d26ef SHA-1: 57f0c5f5232ff9c9f35bd69570ecad94d3dc0dc2 SHA-256: 827b3aeb8767e0cbd2cbe0f359b6776964045522cd73487f57711b5e22772857
4 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF document contains multiple embedded URLs pointing to domains related to stress relief and self-help. While some URLs are confirmed benign, several remain unverified and are likely used for malicious purposes such as phishing or directing users to sites that host malware. The document body is heavily obfuscated, preventing a clear understanding of its specific lure, but the presence of numerous external links is a strong indicator of malicious intent.

Machine Learning

  • Nyx PDF Classifier clean score 0.0001

Heuristics 2

  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://beststresshelp.com/ PDF link annotation
    • http://14daystresscure.com/In PDF document text
    • http://weddingstressrelief.org/In PDF document text
    • http://ormanstressrelief.com/sleepbookIn PDF document text
    • http://collegestress.net/In PDF document text
    • http://ormanstressrelief.com/In PDF document text
    • http://beststresshelp.comPDF link annotation
    • http://14daystresscure.comIn PDF document text
    • http://weddingstressrelief.orgIn PDF document text
    • http://collegestress.netIn PDF document text
    • http://ormanstressrelief.comIn PDF document text
    • http://ocsp.verisign.com0In PDF document text
    • http://facebook.com/beststressreliefIn PDF document text
    • http://pinterest.com/docormanIn PDF document text
    • http://linkedin.com/in/ormanstressreliefIn PDF document text
    • http://LinkedIn.com/in/ormanstressreliefIn PDF document text
    • http://crl.microsoft.com/pki/crl/products/CSPCA.crl0HIn PDF document text
    • http://www.microsoft.com/pki/certs/CSPCA.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/tspca.crl0HIn PDF document text
    • http://www.microsoft.com/pki/certs/tspca.crt0In PDF document text
    • http://www.microsoft.com/typographyIn PDF document text
    • http://www.monotype.com/html/mtname/ms_symbol.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlNOTIFICATIONIn PDF document text
    • http://www.monotype.com/html/type/license.htmlIn PDF document text
    • http://crl.verisign.com/ThawteTimestampingCA.crl0In PDF document text
    • http://crl.verisign.com/tss-ca.crl0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0OIn PDF document text
    • http://www.microsoft.com/pki/certs/CodeSignPCA2.crt0In PDF document text
    • http://www.microsoft.com/truetype/fonts/wingdings/YouIn PDF document text
    • http://www.microsoft.com/typography/ctfontshttp://www.fonts.comYouIn PDF document text
    • http://www.microsoft.com/typography/fonts/default.aspxIn PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00022155.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x22155 221948 bytes
SHA-256: 8f679fbf4a710580bd6dd43e1c37a11d875804544ba10c0ec6af5c2ec4cf72b4
font_01_sfnt_off0003437c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3437C 210332 bytes
SHA-256: e4debdb5db0549819f69f5286f8025bdb8fe370fea0ac44cb1ce52fcc473a99e
font_02_sfnt_off00043f69.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x43F69 24332 bytes
SHA-256: ca6c494bb5ef9be7361cfad38425c9e5ec46bc51a29f0a9ed3e0b4866540a7f4
font_03_sfnt_off000470de.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x470DE 28076 bytes
SHA-256: 2bff52f0ee136f42dae64f1287bed0b4858e82c4f089ce000cb0d3a6fb53d440
font_04_sfnt_off0004a471.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4A471 215596 bytes
SHA-256: 43d3a556cd25b6c8577d58bbdb5484e6aee46f0b10bc257f2438896a7fb7ab87
font_05_sfnt_off000616e7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x616E7 154228 bytes
SHA-256: 29bde9676053fdb6adc37cd4ce6679f29d8422850bf0e4bce1620e5c3800f647