Malicious PDF — malware analysis report

Static analysis result for SHA-256 499b7e2956e19fc5…

MALICIOUS

PDF

31.6 KB Created: 2018-06-11 08:35:22 -04:00 Authoring application: wkhtmltopdf 0.12.4 (via Qt 4.8.7)
MD5: d5470eee3261a13225d13a7d208f75d7 SHA-1: 810dfa70ae4f9336433b6f13ce9abf1cca897940 SHA-256: 499b7e2956e19fc5b328937e182c2ec9c5bab6cb47aab309ef1a27aff18c9bd5
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by an ML classifier as malicious and contains heuristics indicating it is a fake download lure. The document body and extracted URLs point to a deceptive attempt to trick users into downloading a file from the provided URLs, likely a secondary payload. No scripts were extracted, but the PDF structure and heuristics suggest a social engineering attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9103

Heuristics 4

  • Fake 'free download' SEO-poisoning PDF critical PDF_SEO_FAKE_DOWNLOAD
    The ML classifier flagged this PDF AND it carries a visual download/call-to-action lure AND an off-domain server-side download-gateway link whose query string names a document payload. This three-signal conjunction is the fake-document / 'free PDF download' SEO-poisoning delivery pattern: the page is padded with benign decoy links to dilute classifier scores while funnelling the victim through the gateway to malware/scareware. Acting only on the conjunction keeps benign download-bearing PDFs from being misflagged.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://uncpbisdegree.com/download3.php?q=study-questions-for-macbeth.pdf
    • http://uncpbisdegree.com/download4.php?q=study-questions-for-macbeth.pdf
    • http://www.shakespeare-online.com/plays/macbeth/macbethresources.html
    • http://maxstudy.org/English/English
    • http://www.shakespeare-online.com/quiz/macbethquiz/macbethquiz1.html
    • http://leavingcertenglish.net/2011/11/macbeth-questions/
    • http://uncpbisdegree.com/1/wicked-poems.pdf
    • http://uncpbisdegree.com/1/trigonometry-refresh-sudoku-mathbits-answer-key.pdf
    • http://uncpbisdegree.com/1/the-letters-of-ernest-hemingway-volume-1-1907-1922-cambridge-edition.pdf
    • http://uncpbisdegree.com/1/wiring-lights-in-series.pdf
    • http://uncpbisdegree.com/1/wire-diagram-6v-ford-899.pdf
    • http://uncpbisdegree.com/1/tiene-futuro-america-latina-villegas-ensayo-economico-series.pdf
    • http://uncpbisdegree.com/1/understanding-environmental-pollution.pdf
    • http://uncpbisdegree.com/1/the-unofficial-guide-to-ethical-hacking-miscellaneous-ankit-fadia.pdf
    • http://uncpbisdegree.com/1/the-suitcase-kid-jacqueline-wilson.pdf
    • http://uncpbisdegree.com/1/vurt-jeff-noon.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.sparknotes.com/shakespeare/macbeth/study-questions/
    • https://www.gradesaver.com/macbeth
    • http://www.sparknotes.com/shakespeare/macbeth/
    • https://www.cliffsnotes.com/literature/m/macbeth/study-help/quiz
    • https://www.cliffsnotes.com/literature
    • https://www.cliffsnotes.com/literature/m/macbeth/macbeth-at-a-glance
    • https://www.gradesaver.com/macbeth/study-guide/summary
    • https://www.enotes.com/topics/macbeth
    • http://go.microsoft.com/fwlink/?LinkId=521839&CLCID=0409
    • http://go.microsoft.com/fwlink/?LinkID=246338&CLCID=0409
    • https://go.microsoft.com/fwlink/?linkid=868922
    • http://go.microsoft.com/fwlink/?LinkID=286759&CLCID=409
    • http://go.microsoft.com/fwlink/?LinkID=617297
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003f5f.bin
0934b50605a114e4bc61edd17de0015b24b9b8e269ccd13b92a182a8154eee91
pdf-font-stream PDF embedded font (sfnt) at offset 0x3F5F 10620 bytes
font_01_sfnt_off000060f5.bin
3dba54917e6bc53dbedc90ece2ec0f742f9d45c5cdf4fff18b477df90b5b8037
pdf-font-stream PDF embedded font (sfnt) at offset 0x60F5 7320 bytes