Malicious PDF — malware analysis report

Static analysis result for SHA-256 0bf8a817e145f7b1…

MALICIOUS

PDF

45.2 KB Created: 2019-04-04 02:38:24 +03:00 Authoring application: Acrobat PDFMaker 7.0 для Word (via Acrobat Distiller 7.0.5 (Windows)) First seen: 2021-06-28
MD5: 43f5585910d81e60eb475bb3865aeadd SHA-1: 7550a58a25739b8795b6bf7d000a6618f446a994 SHA-256: 0bf8a817e145f7b177d83facadc50c96a0fe56dadfd17a461bc8d9b1c77e27d3
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. The ML classifier also flagged the document as malicious. The primary purpose appears to be the distribution of these external links, likely for SEO spam or to serve as a landing page for other malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8812

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/you-ll-live-through-it-facts-about-the-menopause.pdf In PDF document text
    • http://www.gorillawalker.com/the-dawning-place-the-building-of-a-temple.pdfIn PDF document text
    • http://www.gorillawalker.com/the-literature-of-japanese-education-1945-1954.pdfIn PDF document text
    • http://www.gorillawalker.com/super-juice-cleanse-3-day-juice-cleanse-for-weight-loss.pdfIn PDF document text
    • http://www.gorillawalker.com/getting-started-with-the-internet-of-things-connecting-sensors-and.pdfIn PDF document text
    • http://www.gorillawalker.com/the-expedition-to-the-philippines.pdfIn PDF document text
    • http://www.gorillawalker.com/through-the-eyes-of-the-enemy-the-autobiography-of-stanislav.pdfIn PDF document text
    • http://www.gorillawalker.com/by-adam-fisch-md-neuroanatomy-draw-it-to-know-it.pdfIn PDF document text
    • http://www.gorillawalker.com/grab-bag-6-a-gay-erotica-anthology-volume-6.pdfIn PDF document text
    • http://www.gorillawalker.com/betting-strategy-betting-systems-learn-how-to-maximize-your-wins.pdfIn PDF document text
    • http://www.gorillawalker.com/2015-nfhs-boys-lacrosse-rules-book-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/yes-ma-am-no-sir-the-12-essential-steps-for.pdfIn PDF document text
    • http://www.gorillawalker.com/taking-aim-at-the-arms-trade.pdfIn PDF document text
    • http://www.gorillawalker.com/sophocles-philoctetes-and-the-great-soul-robbery-wisconsin-studies-in.pdfIn PDF document text
    • http://www.gorillawalker.com/cambridge-primary-science-stage-1-activity-book-cambridge-international-examinations.pdfIn PDF document text
    • http://www.gorillawalker.com/the-storm-murders-a-thriller.pdfIn PDF document text
    • http://www.gorillawalker.com/special-effects-new-histories-theories-contexts.pdfIn PDF document text
    • http://www.gorillawalker.com/co2-storage-in-carboniferous-formations-and-abandoned-coal-mines.pdfIn PDF document text
    • http://www.gorillawalker.com/out-of-the-middle-east-the-emergence-of-an-arab.pdfIn PDF document text
    • http://www.gorillawalker.com/perinatal-medicine-v-1-clinical-and-biochemical-aspects.pdfIn PDF document text
    • http://www.gorillawalker.com/materials-management-systems-a-modular-library.pdfIn PDF document text
    • http://www.gorillawalker.com/six-stages-of-forgiving-others-a-spirit-led-adventure.pdfIn PDF document text
    • http://www.gorillawalker.com/statistical-analysis-of-behavioural-data-an-approach-based-on-time.pdfIn PDF document text
    • http://www.gorillawalker.com/mathematics-without-numbers-towards-a-modal-structural-interpretation-clarendon-paperbacks.pdfIn PDF document text
    • http://www.gorillawalker.com/nursing-informatics-91-proceedings-of-the-post-conference-on-health.pdfIn PDF document text
    • http://www.gorillawalker.com/mosby-s-guide-to-nursing-diagnosis-1e.pdfIn PDF document text
    • http://www.gorillawalker.com/avodath-hakodesh-sacred-service-vocal-score.pdfIn PDF document text
    • http://www.gorillawalker.com/the-essential-chronology-star-wars.pdfIn PDF document text
    • http://www.gorillawalker.com/costa-rica-a-visit-to.pdfIn PDF document text
    • http://www.gorillawalker.com/that-mitchell-webb-sound-radio-series-four-bbc-radio-program.pdfIn PDF document text
    • http://www.gorillawalker.com/darkroom-handbook.pdfIn PDF document text
    • http://www.gorillawalker.com/beneath-a-highland-moon-the-highland-moon-series-book-1.pdfIn PDF document text
    • http://www.gorillawalker.com/special-integral-functions-used-in-wireless-communications-theory.pdfIn PDF document text
    • http://www.gorillawalker.com/costa-rica-a-global-studies-handbook-global-studies-latin-america.pdfIn PDF document text
    • http://www.gorillawalker.com/how-to-cope-with-splitting-up-overcoming-common-problems.pdfIn PDF document text
    • http://www.gorillawalker.com/los-mejores-chistes-de-curas-y-monjas-r-ete-con.pdfIn PDF document text
    • http://www.gorillawalker.com/petri-lescaloperii-humanitas-theologica-in-qua-m-t-cicero-de.pdfIn PDF document text
    • http://www.gorillawalker.com/a-family-for-christmas.pdfIn PDF document text
    • http://www.gorillawalker.com/pressure-ulcer-research-etiology-assessment-and-early-intervention-national-pressure.pdfIn PDF document text
    • http://www.gorillawalker.com/design-for-production-manual-volume-3-the-application-of-production.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text