Malicious PDF — malware analysis report

Static analysis result for SHA-256 8e8853636500c9aa…

MALICIOUS

PDF

45.9 KB Created: 2020-04-23 00:01:39 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: e588bb599774e1762d51edf5a6822d26 SHA-1: 1cc582393b8fc67d084ecfd0e9d950455b587231 SHA-256: 8e8853636500c9aa60635b477e47d9badedebe41c799417c9dde9159752944a3
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous external links, many of which are structured in a way that suggests a link farm or SEO manipulation tactic. The document body, though partially corrupted, contains text related to "bounce dryer sheets alternative uses" and references the wkhtmltopdf tool, indicating it was likely generated programmatically. The presence of multiple unknown URLs strongly suggests a phishing or redirection attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9969

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://nicholamaria.com/uploads/1/3/0/7/130738778/130738778.html#bounce+dryer+sheets+alternative+uses
    • http://mariamforcouncil.com/uploads/1/3/0/5/130551226/194349daa.pdf
    • http://lovelettersfrommyex.com/uploads/1/3/0/6/130603942/xisasojegu-nunarutakifiviz-kebipolebajib.pdf
    • http://pacrimedu.com/uploads/1/3/0/7/130775219/4582192.pdf
    • http://penpies.com/uploads/1/3/0/5/130545884/94f11d58.pdf
    • http://specialopsk9.com/uploads/1/3/1/3/131381130/xuzevuvugevude-likaza-pizasepe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008bb3.bin
af27d5d1c9fcab63cc4eb74c73ba7aa105cc7bca66c3febc2a2a9a1969955743
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BB3 8368 bytes