Malicious PDF — malware analysis report

Static analysis result for SHA-256 1dee8c9023db3f92…

MALICIOUS

PDF

43.1 KB Created: 2018-12-05 11:09:31 +03:00 Authoring application: C2 v4.2.0220 build 670 - c2_rendition_config : Techlit_Active (via Acrobat Distiller 10.0.0 (Windows); modified using iText 2.1.7 by 1T3XT) First seen: 2019-02-04
MD5: e477e54d1f11564e51f3274389484ea4 SHA-1: 48199c7b8e979e847863e9f7a4ce10f132a44289 SHA-256: 1dee8c9023db3f92f508dd68066e362f05e608e0def1808f7bf98b1b42bc4cb4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains multiple external URIs pointing to PDF documents on the same domain. The ML classifier flagged this PDF as malicious with a high score. The presence of these URIs suggests an attempt to redirect the user to download further content, likely malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8872

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/effigy-tumuli-the-reemergence-of-ancient-mound-building.pdf In PDF document text
    • http://www.gorillawalker.com/black-keys-the-colorblind-trilogy-volume-1.pdfIn PDF document text
    • http://www.gorillawalker.com/torquay-united-f-c-a-dramatic-year-in-the-life.pdfIn PDF document text
    • http://www.gorillawalker.com/prison-of-dreams.pdfIn PDF document text
    • http://www.gorillawalker.com/christina-cooks-everything-you-always-wanted-to-know-about-whole.pdfIn PDF document text
    • http://www.gorillawalker.com/environmental-impacts-of-sugar-production-cabi.pdfIn PDF document text
    • http://www.gorillawalker.com/grammar-moves-shaping-who-you-are.pdfIn PDF document text
    • http://www.gorillawalker.com/the-making-of-an-authentic-validated-prophet.pdfIn PDF document text
    • http://www.gorillawalker.com/albinus-and-the-history-of-middle-platonism.pdfIn PDF document text
    • http://www.gorillawalker.com/discharge-characteristics-iahr-hydraulic-structures-design-manuals-8-iahr-design.pdfIn PDF document text
    • http://www.gorillawalker.com/perianesthesia-nursing-a-critical-care-approach.pdfIn PDF document text
    • http://www.gorillawalker.com/the-juvenile-justice-system-delinquency-processing-and-the-law-6th.pdfIn PDF document text
    • http://www.gorillawalker.com/our-country-s-regions-prac-act-workbk.pdfIn PDF document text
    • http://www.gorillawalker.com/chronicles-of-a-detroit-railfan-volume-2-across-the-detroit.pdfIn PDF document text
    • http://www.gorillawalker.com/vicious-vocabulary.pdfIn PDF document text
    • http://www.gorillawalker.com/the-billionaire-s-associate-box-set-stories-6-10-billionaire.pdfIn PDF document text
    • http://www.gorillawalker.com/dope-deal.pdfIn PDF document text
    • http://www.gorillawalker.com/hex-the-running-skeletons.pdfIn PDF document text
    • http://www.gorillawalker.com/comparative-evaluations-of-innovative-fisheries-management-global-experiences-and-european.pdfIn PDF document text
    • http://www.gorillawalker.com/subject-of-documentary-visible-evidence.pdfIn PDF document text
    • http://www.gorillawalker.com/the-structure-of-love.pdfIn PDF document text
    • http://www.gorillawalker.com/sacred-influence-what-a-man-needs-from-his-wife-to.pdfIn PDF document text
    • http://www.gorillawalker.com/meeting-the-needs-of-your-most-able-pupils-mathematics-the.pdfIn PDF document text
    • http://www.gorillawalker.com/spatial-planning-systems-of-britain-and-france-a-comparative-analysis.pdfIn PDF document text
    • http://www.gorillawalker.com/no-chariot-let-down-charleston-s-free-people-on-the.pdfIn PDF document text
    • http://www.gorillawalker.com/women-who-write-from-the-past-and-the-present-to.pdfIn PDF document text
    • http://www.gorillawalker.com/baedeker-s-austria-aa-baedeker-s.pdfIn PDF document text
    • http://www.gorillawalker.com/colonel-wm-t-mclyman-stransformer-and-inductor-design-handbook-fourth.pdfIn PDF document text
    • http://www.gorillawalker.com/temptation-goodnight-kiss-goodnight-kiss-2-the-vampire-club.pdfIn PDF document text
    • http://www.gorillawalker.com/cruise-guide-to-europe-and-the-mediterranean-dk-eyewitness-travel.pdfIn PDF document text
    • http://www.gorillawalker.com/architecture-in-salem.pdfIn PDF document text
    • http://www.gorillawalker.com/love-tactics-how-to-win-the-one-you-want.pdfIn PDF document text
    • http://www.gorillawalker.com/opengrounds-at-the-university-of-virginia-link-learn-lead-live.pdfIn PDF document text
    • http://www.gorillawalker.com/night-horrors-immortal-sinners-vampire.pdfIn PDF document text
    • http://www.gorillawalker.com/manuela-novela-de-costumbres-colombianas-tomo-segundo-scholar-s-choice.pdfIn PDF document text
    • http://www.gorillawalker.com/slugs.pdfIn PDF document text
    • http://www.gorillawalker.com/blues-harmonica-playalongs-english-edition-w-audio-cd.pdfIn PDF document text
    • http://www.gorillawalker.com/pterodactyl-dinosaurs.pdfIn PDF document text
    • http://www.gorillawalker.com/the-flower-that-never-fades.pdfIn PDF document text
    • http://www.gorillawalker.com/handbook-of-detergents-part-d-formulation-surfactant-science.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text