Malicious PDF — malware analysis report

Static analysis result for SHA-256 af8a45ead5025c31…

MALICIOUS

PDF

153.0 KB Created: 2015-06-28 20:50:02 -07:00 Authoring application: Microsoft® Word 2010 First seen: 2026-05-31
MD5: 905d142a4c2e585064333cbd1b384d2c SHA-1: f9c5a0ef0db4278f5d1479290f2d4b1acb5d49f2 SHA-256: af8a45ead5025c31e7825cf67b1b18e5b99f3dc4fe46581620d360222b8652d2
136 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.5146

Heuristics 6

  • Image-only PDF lure links through URL shortener high PDF_IMAGE_LURE_SHORTENER_LINK
    PDF is image-heavy with little real text and its clickable action points to a URL shortener. This is a high-confidence credential-phishing carrier shape: the visible page is a screenshot-like prompt while the destination is hidden behind redirect infrastructure.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 2 text block(s), carries a click-outward action, and is only 153 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://astora.z13.web.core.windows.net/dwr.html#&page=_wetransfer2&pcnt=3 In PDF document text
    • http://dthgs.altervista.org/ADOBE.htmlPDF link annotation
    • http://tinyurl.com/ozqhtwfIn PDF document text
    • http://tinyurl.com/pagdae9In PDF document text
    • http://tinyurl.com/oplpc24In PDF document text
    • http://tinyurl.com/nowo5hkIn PDF document text
    • http://tinyurl.com/nnl3l2kIn PDF document text
    • http://tinyurl.com/o2pohe7In PDF document text
    • http://tinyurl.com/p2ozqc6In PDF document text
    • http://tinyurl.com/o724wftIn PDF document text
    • http://tinyurl.com/pt5c5doIn PDF document text
    • http://tinyurl.com/nt673kpIn PDF document text
    • http://tinyurl.com/q78fcdxIn PDF document text
    • http://tinyurl.com/pbuvsosIn PDF document text
    • http://tinyurl.com/naqha9zIn PDF document text
    • http://tinyurl.com/q9rdpzjIn PDF document text
    • http://tinyurl.com/nr6w782In PDF document text
    • http://tinyurl.com/psxr3ptIn PDF document text
    • http://tinyurl.com/ogcl28mIn PDF document text
    • http://tinyurl.com/ozqhtwf)/TypeIn PDF document text
    • http://tinyurl.com/o2pohe7)/TypeIn PDF document text
    • http://tinyurl.com/p2ozqc6)/TypeIn PDF document text
    • http://tinyurl.com/o724wft)/TypeIn PDF document text
    • http://tinyurl.com/pt5c5do)/TypeIn PDF document text
    • http://tinyurl.com/q78fcdx)/TypeIn PDF document text
    • http://tinyurl.com/pbuvsos)/TypeIn PDF document text
    • http://tinyurl.com/naqha9z)/TypeIn PDF document text
    • http://tinyurl.com/q9rdpzj)/TypeIn PDF document text
    • http://tinyurl.com/nr6w782)/TypeIn PDF document text
    • http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYouIn PDF document text
    • http://www.microsoft.com/typography/fonts/default.aspxIn PDF document text
    • http://crl.microsoft.com/pki/crl/products/CSPCA.crl0HIn PDF document text
    • http://www.microsoft.com/pki/certs/CSPCA.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/tspca.crl0HIn PDF document text
    • http://www.microsoft.com/pki/certs/tspca.crt0In PDF document text
    • http://www.microsoft.com/typographyIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f265.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF265 169476 bytes
SHA-256: a6eacb5f4c318f191f5c7ef56b8a9d24965db43dd12e86dc8eafc984e1163d47