PDF static analysis report

Static analysis result for SHA-256 e2c6ee31563e5565…

SUSPICIOUS

PDF

258.9 KB Created: 2016-03-30 11:28:16 UTC Authoring application: PDFescape Online - https://www.pdfescape.com (via RAD PDF 3.19.2.2 - https://www.radpdf.com) First seen: 2021-09-15
MD5: 69f5b91c5fdab7c1b8a4bedc1b0d0335 SHA-1: 137dda0eb93c7e836523b8eff21cdd8cbb4729b7 SHA-256: e2c6ee31563e5565a058679f228b39bd963f70eed6f84d1e439a14c82e3b85e6
54 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF is identified as an image-only lure, typical of phishing campaigns, containing a clickable link to 'https://tr.im/AlTvW'. While the document body contains multiple URLs, the primary suspicious URL is the tr.im shortener, which likely redirects to a malicious site. No scripts were extracted, but the overall structure and heuristic firings suggest a phishing or malware delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8703

Heuristics 3

  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 1 text block(s), carries a click-outward action, and is only 258 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://tr.im/AlTvW PDF link annotation
    • https://online.wiflix.eu/bundles/sonataadmin/csv/In PDF document text
    • https://www.radpdf.comIn PDF document text
    • https://www.radpdf.com)/RadPdfCustomData(pdfescape.com-open-06DA1675262B9AB740849A7AAAEC56695E4FEF0E4C806205)/Creator(PDFescapeIn PDF document text
    • https://www.pdfescape.com)/CreationDate(D:20160330112816Z)/ModDate(D:20210906041554ZIn PDF document text
    • http://www.dynaforms.comIn PDF document text
    • http://resultboxes2.myjino.ru/karrk/indexs.phpIn PDF document text
    • https://okaforo813.wixsite.com/websiteIn PDF document text
    • https://okaforo813.wixsite.com/01mailIn PDF document text
    • https://form.123formbuilder.com/5984150/formIn PDF document text
    • https://form.123formbuilder.com/5989495/mail-ruIn PDF document text
    • https://www.pdfescape.comIn PDF document text
    • http://www.iec.chIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYouIn PDF document text
    • http://www.microsoft.com/typography/fonts/default.aspxIn PDF document text
    • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XIn PDF document text
    • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl0ZIn PDF document text
    • http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn PDF document text
    • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In PDF document text
    • http://www.microsoft.com/Typography/0In PDF document text
    • http://www.microsoft.com/typographyIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off00000aed.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xAED 173484 bytes
SHA-256: f3bf9704ae1a1b01d6eaba8c4203245dfddd8957cdd25f52cca46afe823164ba
font_01_sfnt_off0001400a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1400A 73728 bytes
SHA-256: d43e7b69e1e25fe070d522da94c4396003aae12eb7a75aecb2cc0f5e5feef6a6