Malicious PDF — malware analysis report

Static analysis result for SHA-256 2cb76e5c322f7254…

MALICIOUS

PDF

44.8 KB Created: 2020-06-25 19:45:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e890e529f025371a8782cace0e25f0a1 SHA-1: 029ce7e58ca2e5311312b6cf5bc8613e588730de SHA-256: 2cb76e5c322f7254c0eb6c569d3dfef5ce2c98d251594dba29484a6b44c26b3a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded URLs, many of which are part of a link farm designed to appear as search engine results. The document body, though heavily obfuscated, contains references to 'Ricoh aficio mp 3351 manual usuario' and includes many of these suspicious URLs. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm, suggesting the primary goal is to redirect users to potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://msgarletts-hancock.com/uploads/1/3/0/9/130969533/130969533.html#ricoh+aficio+mp+3351+manual+usuario
    • http://webmail.pullpal.com/uploads/1/3/0/6/130639647/jafisoxipozakujugek.pdf
    • http://mobilecenterz.net/uploads/1/3/1/3/131378913/vewokigido.pdf
    • http://ladiesofhiphopfestival.org/uploads/1/3/1/3/131383820/baferatixaka.pdf
    • http://computersny.com/uploads/1/3/2/7/132712120/gukivumiwe-tizubomifeneg-lizaxubowup-tasut.pdf
    • http://artsoppi.com/uploads/1/3/0/8/130813837/aff2707ae15.pdf
    • http://bloomco.shop/uploads/1/3/0/4/130483200/lusezonojeru-jodov-paxexogeror-kipoxasevowux.pdf
    • http://deutsh.travelmittelamerika.com/uploads/1/3/0/6/130639869/9663244.pdf
    • http://thecountrycraftfair.com/uploads/1/3/1/8/131856052/ramezaweluwi_zoraw_bujona_newerapiza.pdf
    • https://vamuxep.files.wordpress.com/2020/06/33733637474.pdf
    • https://figanupa.files.wordpress.com/2020/06/wuvipim.pdf
    • https://nutolusajom.files.wordpress.com/2020/06/zisis.pdf
    • https://difadukes.files.wordpress.com/2020/06/laredusoputal.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000055e9.bin
c23b4e7fca414baf5710e3c4e6685a20561588d97b09aede579d92d06837a69e
pdf-font-stream PDF embedded font (sfnt) at offset 0x55E9 5284 bytes
font_01_sfnt_off000067b8.bin
a4dd6ea6c772249438b13f6f73953dd20a93fe1e354f538cf6c8b9a97ef85f1e
pdf-font-stream PDF embedded font (sfnt) at offset 0x67B8 12796 bytes
font_02_sfnt_off00008f87.bin
e343998647cbc530d0d761dc446f250f3160ceeca97e4e9775203fb497d102f0
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F87 16684 bytes