Malicious PDF — malware analysis report

Static analysis result for SHA-256 1bb163d6fc0426da…

MALICIOUS

PDF

42.4 KB Created: 2018-12-15 20:01:41 +03:00 Authoring application: dvips(k) 5.993 Copyright 2013 Radical Eye Software (via GPL Ghostscript 9.07)
MD5: faeab761e103a992245926b92f2d3e72 SHA-1: 68b7997cf7f1d883607d646dbb06313798529793 SHA-256: 1bb163d6fc0426dad4bff8d1dd819e7528f9a77ee75b0f3ef1714798f3160d39
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged the document as malicious. The primary attack pattern appears to be a link farm designed to manipulate search engine results or distribute malicious content via numerous links. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8872

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/search-for-the-purebloods-oklahoma-museum-of-natural-history.pdf
    • http://www.gorillawalker.com/nanosensors-physical-chemical-and-biological-series-in-sensors.pdf
    • http://www.gorillawalker.com/no-regret.pdf
    • http://www.gorillawalker.com/laser-guidebook.pdf
    • http://www.gorillawalker.com/the-archaeology-of-social-boundaries-smithsonian-series-in-archaeological-inquiry.pdf
    • http://www.gorillawalker.com/the-vor-game.pdf
    • http://www.gorillawalker.com/3-pi-ces-pour-orchestre-op-96-valse-chevaleresque-no.pdf
    • http://www.gorillawalker.com/bad-boys-an-inside-look-at-the-detriot-piston-s.pdf
    • http://www.gorillawalker.com/robert-wilson-routledge-performance-practitioners.pdf
    • http://www.gorillawalker.com/the-fire-and-the-light-book-one-of-the-souls.pdf
    • http://www.gorillawalker.com/cultural-roundabouts-spanish-film-and-novel-on-the-road.pdf
    • http://www.gorillawalker.com/venza-sus-temores-ansiedad-fobia-y-p-nico-masters-salud.pdf
    • http://www.gorillawalker.com/landon-and-the-leatherback-sea-turtle.pdf
    • http://www.gorillawalker.com/there-are-no-problem-horses-only-problem-riders.pdf
    • http://www.gorillawalker.com/fluid-structure-interactions-cross-flow-induced-instabilities.pdf
    • http://www.gorillawalker.com/fuerzas-especiales-largo-recorrido-spanish-edition.pdf
    • http://www.gorillawalker.com/how-to-gamble-if-you-must-inequalities-for-stochastic-processes.pdf
    • http://www.gorillawalker.com/governor-s-hot-kinky-wife-interracial-obsessions-volume-two.pdf
    • http://www.gorillawalker.com/transitions-leading-churches-through-change.pdf
    • http://www.gorillawalker.com/fallen-secrets-kindle-edition.pdf
    • http://www.gorillawalker.com/james-journey-to-the-amusement-park.pdf
    • http://www.gorillawalker.com/le-black-cat-saloon-french-edition.pdf
    • http://www.gorillawalker.com/the-ibanker-kindle-edition.pdf
    • http://www.gorillawalker.com/delicious-the-art-and-life-of-wayne-thiebaud.pdf
    • http://www.gorillawalker.com/the-fallen-sentinel.pdf
    • http://www.gorillawalker.com/your-mba-game-plan-third-edition-proven-strategies-for-getting.pdf
    • http://www.gorillawalker.com/the-ferrari-in-the-bedroom.pdf
    • http://www.gorillawalker.com/essentials-of-psychiatric-mental-health-nursing-concepts-of-care-in.pdf
    • http://www.gorillawalker.com/mussette-in-d-major-bwv-anh-126-early-intermediate-piano.pdf
    • http://www.gorillawalker.com/el-necronomicon-spanish-edition.pdf
    • http://www.gorillawalker.com/st-dragon-girl-vol-5.pdf
    • http://www.gorillawalker.com/marine-insurance-origins-and-institutions-1300-1850-palgrave-studies-in.pdf
    • http://www.gorillawalker.com/the-handbook-of-international-marketing-communications.pdf
    • http://www.gorillawalker.com/foreclosure-survival-guide-the-keep-your-house-or-walk-away.pdf
    • http://www.gorillawalker.com/hotel-organisation-and-front-office-management.pdf
    • http://www.gorillawalker.com/annotated-guide-to-robert-e-howard-s-sword-and-sorcery.pdf
    • http://www.gorillawalker.com/the-proposition-book-2-illicit-proposition-billionaire-boss.pdf
    • http://www.gorillawalker.com/linking-objects-and-linking-phenomena.pdf
    • http://www.gorillawalker.com/the-postcolonial-studies-dictionary.pdf
    • http://www.gorillawalker.com/modern-mix-curating-personal-style-with-chic-accessible-finds.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/