Malicious PDF — malware analysis report

Static analysis result for SHA-256 305ec90a4ddfcfe0…

MALICIOUS

PDF

37.1 KB Created: 2020-06-20 09:15:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 022632ff12c81a6b12cbd61fd0e866be SHA-1: fdbb656a8e993e7bb3cba117cca3885cc74583ac SHA-256: 305ec90a4ddfcfe0165f5813bdf957051ff8fc17e9fc6c2a82f93503eaa93c60
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF file was flagged by a machine learning classifier as malicious. It contains a large number of external links, many of which point to PDFs hosted on various domains, suggesting a link farm or redirection strategy. The document body mentions 'Ontario boat license study guide' and includes URLs that appear to be part of this lure, likely directing users to malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cyberliabilitypro.com/uploads/1/3/0/8/130814245/130814245.html#ontario+boat+license+study+guide
    • http://shut-the-front-door-properties.com/uploads/1/3/0/4/130477152/kutudisivikuleze.pdf
    • http://goelcommunity.com/uploads/1/3/0/6/130621715/gumotezi_gabir_felegom.pdf
    • http://webdisk.wilesbolt.com/uploads/1/3/0/2/130289625/448089.pdf
    • http://swanksrock.com/uploads/1/3/0/3/130379841/59d6e78d49.pdf
    • http://oldaleandsons.org/uploads/1/3/1/3/131384113/4011499.pdf
    • http://drroddysuos.com/uploads/1/3/0/7/130775651/xiwiwigi.pdf
    • http://purrfectgoldenpuppies.com/uploads/1/3/0/2/130289474/sojikajigipumizik.pdf
    • http://mail.teachenglishstepbystep.com/uploads/1/3/1/6/131637797/besizod.pdf
    • http://webmail.vulcantri.com/uploads/1/3/1/6/131636814/velitixu.pdf
    • http://1em.undesirable.us/uploads/1/3/1/4/131437348/ba400ce0.pdf
    • http://cpanel.monticellosmarket.com/uploads/1/3/2/7/132741430/lefofuzisubinufexaje.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004f39.bin
69527174c5ac9a6b33c42fce7c8a3fac9880ac8c24deaf110eb5d64ec6fefc86
pdf-font-stream PDF embedded font (sfnt) at offset 0x4F39 5260 bytes
font_01_sfnt_off0000611a.bin
67efff686a9ff7cf75624814e48b531a4448fb6925b7592369b488f5e2fd0070
pdf-font-stream PDF embedded font (sfnt) at offset 0x611A 11500 bytes