Malicious PDF — malware analysis report

Static analysis result for SHA-256 091ad687cd8de144…

MALICIOUS

PDF

53.2 KB Created: 2018-06-11 08:51:53 -04:00 Authoring application: wkhtmltopdf 0.12.4 (via Qt 4.8.7)
MD5: 43632a7c4b8146d27545e1c587ff8a9f SHA-1: cea394d2d4206d4d3e430ab65ae10953704b3b21 SHA-256: 091ad687cd8de144b946a66e1d1b2da188457f020fe1a4fd64df1c208d35774b
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, many of which are disguised as educational resources, specifically targeting Spanish workbook answers. The heuristic 'PDF_SEO_FAKE_DOWNLOAD' and 'PDF_SEO_LINK_FARM' indicate that this is a SEO poisoning attempt to trick users into downloading a malicious file from URLs like http://uncpbisdegree.com/download3.php?q=vista-higher-learning-spanish-workbook-answers-leccion-6.pdf. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7285

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake 'free download' SEO-poisoning PDF critical PDF_SEO_FAKE_DOWNLOAD
    The ML classifier flagged this PDF AND it carries a visual download/call-to-action lure AND an off-domain server-side download-gateway link whose query string names a document payload. This three-signal conjunction is the fake-document / 'free PDF download' SEO-poisoning delivery pattern: the page is padded with benign decoy links to dilute classifier scores while funnelling the victim through the gateway to malware/scareware. Acting only on the conjunction keeps benign download-bearing PDFs from being misflagged.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://uncpbisdegree.com/download3.php?q=vista-higher-learning-spanish-workbook-answers-leccion-6.pdf
    • http://uncpbisdegree.com/download4.php?q=vista-higher-learning-spanish-workbook-answers-leccion-6.pdf
    • http://spanishclassteixeira.weebly.com/uploads/1/3/2/4/13241249/l06_answers_cuaderno_de_practica.pdf
    • http://habnix.de/vista/higher/vista_higher_learning_spanish_workbook_answers_leccion_6.pdf
    • http://riverside-resort.net/pdfs/leccion-6-vhl-answer-key.pdf
    • https://vistahigherlearning.com/
    • https://hjagroup.co.uk/books/2360a9/vista_higher_learning_spanish_workbook_answers_leccion_6_pdf.pdf
    • http://uncpbisdegree.com/download/vhlcentral-answer-key-leccion-7.pdf
    • http://uncpbisdegree.com/1/the-yellow-bird-classic-adventures.pdf
    • http://uncpbisdegree.com/1/vahid-solutions.pdf
    • http://uncpbisdegree.com/1/yamaha-majesty-yp125-r-service-manual.pdf
    • http://uncpbisdegree.com/1/the-long-mars-earth-3-terry-pratchett.pdf
    • http://uncpbisdegree.com/1/volvo-xc70-check-engine.pdf
    • http://uncpbisdegree.com/1/why-is-oklahoma-having-so-many-earthquakes-2016.pdf
    • http://uncpbisdegree.com/1/world-of-genetics-answer-key.pdf
    • http://uncpbisdegree.com/1/troubleshooting-electronic-equipment.pdf
    • http://uncpbisdegree.com/1/twelve-days-teresa-hill.pdf
    • http://uncpbisdegree.com/1/the-sunday-times-concise-crossword-book-4-bk-4.pdf
    • https://vistahigherlearning.com
    • https://hjagroup.co.uk/books/2360a9/vista_higher_learning_spanish
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://www.coursehero.com/file/13745341/Workbook-Answer-Key/
    • http://docplayer.net/31130600-Vista-higher-learning-descubre-2-workbook-answers.html
    • https://quizlet.com/subject/vista-higher-learning/
    • https://www.youtube.com/watch?v=fpW4_FPTIgo
    • https://www.youtube.com/watch?v=ltOFWIHiFgw
    • https://quizlet.com/subject/spanish-vocab-descubre-vista-higher-learning/
    • http://go.microsoft.com/fwlink/?LinkID=617350
    • http://go.microsoft.com/fwlink/?LinkId=521839&CLCID=0409
    • http://go.microsoft.com/fwlink/?LinkID=246338&CLCID=0409
    • https://go.microsoft.com/fwlink/?linkid=868922
    • http://go.microsoft.com/fwlink/?LinkID=286759&CLCID=409
    • http://go.microsoft.com/fwlink/?LinkID=617297
    • https://www.coursehero.com/file/13745341/Workbook-Answer-Key
    • https://quizlet.com/subject/vista-higher-learning
    • https://quizlet.com/.../spanish-vocab-descubre-vista-higher-learning
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007fdc.bin
83cdd196cb5d65191c7f730179b6e82af9ce5b999bf47ef416c0f55231e1e299
pdf-font-stream PDF embedded font (sfnt) at offset 0x7FDC 15436 bytes
font_01_sfnt_off0000ad11.bin
9e51310e75dfaa7a84898a66d23eff1e8b05a0d9f65fcacf849dcc243e98a0b9
pdf-font-stream PDF embedded font (sfnt) at offset 0xAD11 9496 bytes