PDF static analysis report

Static analysis result for SHA-256 8907866ca24b1dc6…

SUSPICIOUS

PDF

200.0 KB Created: 2017-08-16 22:41:15 UTC Authoring application: RAD PDF (via RAD PDF 3.4.6.2 - http://www.radpdf.com) First seen: 2019-06-27
MD5: e2430e17a2a73142bb91fa32d44f61d5 SHA-1: 766f5e2e03aa8edc15fb717f7dfb1cccd1e1d51d SHA-256: 8907866ca24b1dc6761e6cd92446dd4eb65e13aa4c3a57cb9f09c97dcac2b008
50 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document uses a cloud document lure, impersonating services like OneDrive, to trick the user into clicking a shortened URL. This URL likely leads to a malicious site designed to host and deliver a secondary payload. The presence of multiple shortened and direct URLs, some pointing to suspicious domains, supports this attack pattern.

Machine Learning

  • Nyx PDF Classifier clean score 0.0095

Heuristics 4

  • Clickable URI uses URL shortener medium PDF_URL_SHORTENER_URI
    PDF contains a clickable HTTP(S) action whose destination is a URL shortener. This hides the final landing page from static review and is common in phishing redirect PDFs.
  • Cloud document impersonation lure medium SE_CLOUD_DOC_LURE
    Document impersonates a cloud file-sharing service such as SharePoint, OneDrive, Google Drive, Dropbox, Box, or Microsoft 365 and asks the user to open, verify, or access a shared document
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bilaltextiles.com/newyear/xb/ In PDF document text
    • https://mselhyaeyrh.global/new/newyear/xb/In PDF document text
    • https://storage.googleapis.com/onedrive-cacked-679968778/login.htmlIn PDF document text
    • https://storage.googleapis.com/onedrive-standees-868342590/login.htmlIn PDF document text
    • http://www.radpdf.comIn PDF document text
    • http://www.radpdf.com)/Author(Dell)/Creator(RADIn PDF document text
    • http://www.dynaforms.comIn PDF document text
    • http://ow.ly/JDBW30ereaTIn PDF document text
    • http://ow.ly/MBFN30eizetIn PDF document text
    • https://bit.ly/2HeavJKIn PDF document text
    • https://bit.ly/2Nvcr4WIn PDF document text
    • https://bit.ly/2LnGuguIn PDF document text
    • https://bit.ly/2AREysTIn PDF document text
    • https://bit.ly/2MpSy2tIn PDF document text
    • https://bit.ly/2MRQyzmIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comMicrosoftIn PDF document text
    • http://www.microsoft.com/typography/fonts/default.aspxIn PDF document text
🗂 Part of campaign: radpdf.com) 3 samples

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off00001da2.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1DA2 233184 bytes
SHA-256: 4471f10a6ba4ca6b5099ccb4e83508ecfdf3cc0caa7b520b3eb92d5fee926fc7