PDF static analysis report

Static analysis result for SHA-256 eecfe7a4e08d22c7…

SUSPICIOUS

PDF

214.0 KB Created: 2016-10-26 12:57:49 +01:00 Authoring application: RAD PDF (via RAD PDF 2.36.6.2 - http://www.radpdf.com) First seen: 2026-05-04
MD5: 3998b9475835198f4be7be9c5449d861 SHA-1: 75bc26e9e01f31cd8c4baef4c5059f300d5e046c SHA-256: eecfe7a4e08d22c75a5334bd4801324a1cee43d0e9edb0960b11c954d8bb2e07
54 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was identified as an image-only document with an action trigger, typical of a phishing lure. The embedded URLs and document body content point to redirection to external websites, likely for credential harvesting or further malware deployment. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8601

Heuristics 3

  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 213 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.blulobster.ca/purchase/newshit/findemall/index.php In PDF document text
    • http://appsa.systems/cbtis198/j/2/Mover/wp_shell/wp_include/shell_directorate/amin_shell/index.phpIn PDF document text
    • http://www.radpdf.comIn PDF document text
    • http://www.radpdf.com)/Creator(RADIn PDF document text
    • http://www.dynaforms.comIn PDF document text
    • https://angelipedrosaribitwo.000webhostapp.com/jese/fgfg/BestPdf/kbkvsdr9fmvwonlizsyycnac.php?rand=13InboxLightaspxn.1774256418&fid.4.1252899642&fid=1&fav.1&rand.13InboxLight.aspxn.1774256418&fid.1252899642&fid.1&fav.1&email=&.rand=13InboxLight.aspx?n=1774256418&fid=4#n=1252899642&fid=1&fav=1PDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYouIn PDF document text
    • http://www.microsoft.com/typography/fonts/default.aspxIn PDF document text
    • http://crl.microsoft.com/pki/crl/products/CSPCA.crl0HIn PDF document text
    • http://www.microsoft.com/pki/certs/CSPCA.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/tspca.crl0HIn PDF document text
    • http://www.microsoft.com/pki/certs/tspca.crt0In PDF document text
    • http://www.microsoft.com/typographyIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000e20.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE20 169476 bytes
SHA-256: a6eacb5f4c318f191f5c7ef56b8a9d24965db43dd12e86dc8eafc984e1163d47