Malicious PDF — malware analysis report

Static analysis result for SHA-256 a02be3aa55ac35d4…

MALICIOUS

PDF

53.0 KB Created: 2018-06-11 08:50:07 -04:00 Authoring application: wkhtmltopdf 0.12.4 (via Qt 4.8.7) First seen: 2020-09-24
MD5: 179174d0c3484efbf960c3039a495401 SHA-1: 973810e9f884dbd20c6a2a1b015ad7d107bff9dc SHA-256: a02be3aa55ac35d4f33584e257bcc174a9d14d661c3b06a3e3fe2e862fe8413c
130 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains multiple links to external websites, including one identified as an external URI pointing to 'http://uncpbisdegree.com/download3.php?q=soldier-2018-recruitment-form.pdf'. The ML classifier flagged this PDF as malicious. The document body text and embedded URLs suggest a lure related to recruitment forms, likely intended to trick users into downloading a secondary payload. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6462

Heuristics 4

  • Fake 'free download' SEO-poisoning PDF critical PDF_SEO_FAKE_DOWNLOAD
    The ML classifier flagged this PDF AND it carries a visual download/call-to-action lure AND an off-domain server-side download-gateway link whose query string names a document payload. This three-signal conjunction is the fake-document / 'free PDF download' SEO-poisoning delivery pattern: the page is padded with benign decoy links to dilute classifier scores while funnelling the victim through the gateway to malware/scareware. Acting only on the conjunction keeps benign download-bearing PDFs from being misflagged.
  • PDF carries a PHP-gateway SEO-spam PDF link farm medium PDF_SEO_PHP_GATEWAY_LINK_FARM
    PDF contains four or more clickable links whose target is a `.php` gateway with a multi-word search-PHRASE document slug embedded after it (e.g. 'index.php?.../binary+options+trading+nz.pdf' or 'pdf.php/cialis-dosage-side-effects.pdf'). Legitimate PHP-served documents use a filename or numeric id, not a search-query phrase, so this is the generated SEO link-farm shape — pharma / binary-options / 'free download' spam that ranks for queries and routes users into payload/redirect chains. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://uncpbisdegree.com/download3.php?q=soldier-2018-recruitment-form.pdf In PDF document text
    • http://uncpbisdegree.com/download4.php?q=soldier-2018-recruitment-form.pdfIn PDF document text
    • https://www.recruitmentformportal.com/nigerian-army-recruitment/In PDF document text
    • https://www.scholarinsider.com/nigerian-army-recruitment-form/In PDF document text
    • http://recruitmentresult.com/indian-army-recruitment-rally/In PDF document text
    • https://careerselection.in/jobs/army-education-havildar-recruitment-2018-2019/In PDF document text
    • http://www.currentschoolnews.com/job/nigerian-army-recruitment-form-guide/In PDF document text
    • https://www.tamilanjobs.com/perambalur-trichy-indian-army-rally-recruitment-2018-apply-online-various-soldier-posts/In PDF document text
    • https://www.basevibe.com/british-army-recruitment-2018-2019-form/In PDF document text
    • http://nevine.de/soldier/2018/soldier_2018_recruitment_form.pdfIn PDF document text
    • https://www.wifistudy.com/assam-riflesIn PDF document text
    • https://schols.com.ng/nigerian-army-77rri-recruitment-form-2018-2019-is-out-how-to-apply/In PDF document text
    • https://www.placementstore.com/indian-army-apply-online-2018/In PDF document text
    • http://riverside-resort.net/1/the-truth-about-princesses.pdfIn PDF document text
    • http://riverside-resort.net/1/smoke-in-the-sand-the-jews-of-lvov-in-the-war-years-1939-1944.pdfIn PDF document text
    • http://riverside-resort.net/1/terapiia-na-kozhnite-i-polovo-predavani-bolesti.pdfIn PDF document text
    • http://riverside-resort.net/1/trane-tcont803as32da-thermostat-installation-manual.pdfIn PDF document text
    • http://riverside-resort.net/1/ufo-revelation-the-secret-technology-exposed.pdfIn PDF document text
    • http://riverside-resort.net/1/technical-service-bulletins-by-vin.pdfIn PDF document text
    • http://riverside-resort.net/1/toyota-vios-service-repair-manual.pdfIn PDF document text
    • http://riverside-resort.net/1/the-rebellion-of-the-hanged.pdfIn PDF document text
    • http://riverside-resort.net/1/study-guide-answer-key.pdfIn PDF document text
    • http://riverside-resort.net/1/twelve-transgressions.pdfIn PDF document text
    • https://www.recruitmentformportal.com/nigerian-army-recruitmentIn PDF document text
    • https://www.scholarinsider.com/nigerian-army-recruitment-formIn PDF document text
    • https://careerselection.in/jobs/army-education-havildarIn PDF document text
    • https://www.tamilanjobs.com/perambalur-trichy-indian-army-rallyIn PDF document text
    • https://www.basevibe.com/british-army-recruitment-2018-2019-formIn PDF document text
    • https://schols.com.ng/nigerian-army-77rri-recruitment-form-2018In PDF document text
    • https://www.placementstore.com/indian-army-apply-online-2018In PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://www.blogarama.com/technology-blogs/334212-dailysgist-reaching-information-needs-blog/22522504-army-recruitment-application-2018-form-apply-hereIn PDF document text
    • http://go.microsoft.com/fwlink/?LinkID=617350In PDF document text
    • http://go.microsoft.com/fwlink/?LinkId=521839&CLCID=0409In PDF document text
    • http://go.microsoft.com/fwlink/?LinkID=246338&CLCID=0409In PDF document text
    • https://go.microsoft.com/fwlink/?linkid=868922In PDF document text
    • http://go.microsoft.com/fwlink/?LinkID=286759&CLCID=409In PDF document text
    • http://go.microsoft.com/fwlink/?LinkID=617297In PDF document text
    • https://www.blogarama.com/technology-blogs/334212-dailysgistIn PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007fd5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7FD5 14148 bytes
SHA-256: 20805099ada7f1a3600fdaffd398ddcbab3e6c218fa4b73c51ea2154267605de
font_01_sfnt_off0000ab4a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAB4A 9612 bytes
SHA-256: 8438e86a35a8f2ea7517b0f4e044971ed1951fbf1bc4eedc897ccf67b5d93500