PDF static analysis report

Static analysis result for SHA-256 ca462a263c3df205…

SUSPICIOUS

PDF

114.1 KB Created: 2020-03-29 23:59:28 +05:00 Authoring application: PDFescape Online - https://www.pdfescape.com (via RAD PDF 3.19.2.2 - https://www.radpdf.com) First seen: 2021-11-25
MD5: 2ff6363f3afb442dac54916fa7bedfa6 SHA-1: 28d6e5ffdb97af839a36573b33e434f8a781c0fd SHA-256: ca462a263c3df20536029a3012e1d475d447ab0fe68d891d35be4b1a93455f00
32 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document exhibits characteristics of a cloud document lure, impersonating services like SharePoint or OneDrive to trick users into clicking a link. The presence of multiple unknown URLs, including one hosted on Backblaze B2, suggests an attempt to redirect the user to a malicious site for further exploitation or payload download. The heuristic for a download button further supports this malicious workflow.

Machine Learning

  • Nyx PDF Classifier clean score 0.0018

Heuristics 4

  • Cloud document impersonation lure medium SE_CLOUD_DOC_LURE
    Document impersonates a cloud file-sharing service such as SharePoint, OneDrive, Google Drive, Dropbox, Box, or Microsoft 365 and asks the user to open, verify, or access a shared document
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://anadoluyakasikuryesi.ru/vcxz/?prime=252020 In PDF document text
    • https://askvideodc.ru/cvbn/?prime=252020In PDF document text
    • https://firebasestorage.googleapis.com/v0/b/e-rygwrg-f8375fg-78.appspot.com/o/db-cbi-w%2Fsb-fvr-u87-gh.html?alt=media&token=bc0042b5-4ebd-411d-9fdc-0929fa9a4a80In PDF document text
    • https://csat-system.com/Project+file/share.htmlIn PDF document text
    • https://eppzamoraeditorial.com/microsoft+project/0001In PDF document text
    • https://chronicdiseaseday.org/zebra+projects/0001In PDF document text
    • https://teahealthychoice.com/business/0001In PDF document text
    • https://eppzamoraeditorial.com/Company/0001In PDF document text
    • https://eppzamoraeditorial.com/Category/0001In PDF document text
    • https://eppzamoraeditorial.com/Responsable/0001In PDF document text
    • https://eppzamoraeditorial.com/documentfile/0001In PDF document text
    • https://recondicionados.pt/Microsoft/0001In PDF document text
    • https://eppzamoraeditorial.com/business2business/0001In PDF document text
    • https://eppzamoraeditorial.com/Manager/0001In PDF document text
    • https://ng.retireearlyasia.com/documentsfile/0001In PDF document text
    • https://eppzamoraeditorial.com/MicrosoftFiles/0001In PDF document text
    • https://ohrc.om/Sammyin/0001In PDF document text
    • https://ohrc.om/business+file/0001In PDF document text
    • https://ohrc.om/onedrive+document/0001In PDF document text
    • https://ohrc.om/DOUCMENTS/0001In PDF document text
    • https://chemdrydifference.com.au/Microsoft+documenets/0001In PDF document text
    • https://chemdrydifference.com.au/business+microsoft/0001In PDF document text
    • https://ekas.com.au/wp-includes/Requests/Auth/user/whiteIn PDF document text
    • https://ekas.com.au/business+file/0001In PDF document text
    • https://ohrc.om/User+project/0001In PDF document text
    • https://ohrc.om/DOCUMENTS/0001In PDF document text
    • https://ohrc.om/businesslimited/0001In PDF document text
    • https://www.ekas.com.au/business+file/0001In PDF document text
    • https://ohrc.om/office+offer/0001In PDF document text
    • https://ohrc.om/MICROSOFT/0001In PDF document text
    • https://purposeoverpain.net/Microsoft+contacts/0001In PDF document text
    • https://purposeoverpain.net/User+files/0001In PDF document text
    • https://purposeoverpain.net/Documents/0001In PDF document text
    • https://purposeoverpain.net/Businesslimited/0001In PDF document text
    • https://ohrc.om/office+files/0001In PDF document text
    • https://4uclean.net/Documentsfile/0001In PDF document text
    • http://4uclean.net/wp-admin/user/kjpIn PDF document text
    • https://ohrc.om/Yahoo+officefiles/0001In PDF document text
    • https://spteam.net/.well-known/Documents/0001In PDF document text
    • http://spteam.net/.well-known/businesslimited/0001In PDF document text
    • https://ohrc.om/project+user/0001In PDF document text
    • https://ohrc.om/Microsoft+smoke/0001In PDF document text
    • https://ohrc.om/business2businesslimited/0001In PDF document text
    • https://spteam.net/wp-content/User/0001In PDF document text
    • https://rkagro.in/Quote/0001In PDF document text
    • https://evolveworld.com/User/0001In PDF document text
    • https://wertvollsolutionsltd.com/url/excelzIn PDF document text
    • https://yachtingrouter.com/Microsoft+file/0001In PDF document text
    • https://www.radpdf.comIn PDF document text
    • https://storage.googleapis.com/lnveoqualnkjnvalneqon2.appspot.com/jbev/ZUXIn PDF document text
    +26 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003b9f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3B9F 81740 bytes
SHA-256: 8968d311fdd8ca6aefb490943eb49835e5a3d5766af51f30fd96e38a9d4f0ea2
font_01_sfnt_off00008a39.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8A39 30292 bytes
SHA-256: afa75e562f45f111dd7afb358418909c24af71a6f0011b56f80f2e96ad59fb9b