Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea7c2144434a3968…

MALICIOUS

PDF

35.1 KB Created: 2018-06-11 08:27:46 -04:00 Authoring application: wkhtmltopdf 0.12.4 (via Qt 4.8.7)
MD5: c6a640c659db9e13c46d640f8d14c739 SHA-1: 6fc37a75cf549f570ee4bd3420599b71fef268c1 SHA-256: ea7c2144434a396828a960665b348c1e84627a5144fbc02353ad5f52a65b7ec3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF contains an external URI pointing to a suspicious URL, and ML classification strongly indicates maliciousness. The presence of PRC/3D content is also a known indicator of malicious PDFs. The document body, though partially garbled, includes URLs that appear to be part of a lure, suggesting the file is designed to trick the user into downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9136

Heuristics 4

  • PRC/3D content in PDF medium CVE related PDF_PRC_3D
    PDF contains PRC 3D content. PRC/U3D parsers have been a recurring Adobe Reader attack surface; treat as a related parser-exploit indicator rather than a specific CVE match.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://uncpbisdegree.com/download3.php?q=truth-peter-temple.pdf
    • http://uncpbisdegree.com/download4.php?q=truth-peter-temple.pdf
    • http://mybodyhistemple.com/
    • http://spiritandtruthministries.org/
    • http://www.crossroad.to/articles2/TwistingTruth.html
    • http://www.thetruthabouthell.net/
    • http://www.truthforkids.com/gospels/
    • http://www.ldsendowment.org/veil.html
    • http://www.aviewoncities.com/rome/mouthoftruth.htm
    • http://www.realjewnews.com/?p=935
    • http://www.betemunah.org/temple.html
    • http://www.realjewnews.com/?p=130
    • http://www.goodnewspirit.com/michael.htm
    • http://www.unitytemple.com/announcements.asp
    • http://biblefacts.org/pdf/Dispensational_Truth.pdf
    • http://www.british-israel.ca/Islam.htm
    • http://remember.org/educate/frank
    • http://cgi.org/what-is-the-real-gospel-truth/
    • http://www.rapturetruth.org/
    • http://bible-truth.org/tongues.html
    • https://www.truthcontrol.com/
    • http://www.foryourmarriage.org/new-testament-readings/
    • http://riverside-resort.net/1/the-lost-treasures-of-london.pdf
    • http://riverside-resort.net/1/summa-theologiae-vol-48-the-incarnate-word-3a-1-6.pdf
    • http://riverside-resort.net/1/soviet-american-rivalry-in-the-middle-east.pdf
    • http://riverside-resort.net/1/the-cognitive-dynamics-of-computer-science-cost-effective-large-scale-software-development.pdf
    • http://riverside-resort.net/1/the-hungry-heart-daily-devotions-from-the-old-testament.pdf
    • http://riverside-resort.net/1/suzuki-lt50-manual.pdf
    • http://riverside-resort.net/1/the-road-to-zero-landfill-western-michigan-university.pdf
    • http://riverside-resort.net/1/toyota-tundra-navi-wiring-diagram.pdf
    • http://riverside-resort.net/1/sociology-final-exam-study-guide.pdf
    • http://riverside-resort.net/1/texas-state-board-of-dental-examiners-complaints.pdf
    • http://riverside-resort.net/1/the-hungry-hear
    • https://en.wikipedia.org/wiki/Peter_Temple
    • https://en.wikipedia.org/wiki/Gospel_of_Truth
    • http://usccb.org/bible/john/21/
    • https://www.catholic.org/encyclopedia/view.php?id=11728
    • https://www.catholic.org/encyclopedia/
    • https://www.catholic.org/encyclopedia/encyclopedia.php
    • http://tbcsermonoutlines.blogspot.com/
    • http://www.usccb.org/bible/john/18/
    • http://biblehub.com/acts/4-1.htm
    • http://go.microsoft.com/fwlink/?LinkId=521839&CLCID=0409
    • http://go.microsoft.com/fwlink/?LinkID=246338&CLCID=0409
    • https://go.microsoft.com/fwlink/?linkid=868922
    • http://go.microsoft.com/fwlink/?LinkID=286759&CLCID=409
    • http://go.microsoft.com/fwlink/?LinkID=617297

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004ebc.bin
4db8a67f2b8d0a8a9589e11691e810627f683aa4ee8473e1fd1b6687af5aae3d
pdf-font-stream PDF embedded font (sfnt) at offset 0x4EBC 10628 bytes
font_01_sfnt_off00007081.bin
d62af5e8b68fda758a8e57ffc1aba8be4a892b42059ea04cf5a19cf5210f6495
pdf-font-stream PDF embedded font (sfnt) at offset 0x7081 6112 bytes