Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e9257c1ef4bc162…

MALICIOUS

PDF

44.7 KB Created: 2018-11-30 20:08:35 +03:00 Authoring application: TeX (via pdfTeX-1.40.16)
MD5: 5fba5d0b7b6dfa7ef93ce398ec4e4b68 SHA-1: 5d2ca72db24f9199e23d018b37c81676b686c10a SHA-256: 1e9257c1ef4bc1626c2aa5cb4c659b8027d7cf651d05d81837c85a43b0fbfba2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a vast collection of documents hosted on 'gorillawalker.com'. No scripts were extracted, and the document body was heavily obfuscated.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8173

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/john-dewey-between-pragmatism-and-constructivism.pdf
    • http://www.gorillawalker.com/brighter-child-at-the-zoo-activity-book-ages-3-6.pdf
    • http://www.gorillawalker.com/memory-and-dream.pdf
    • http://www.gorillawalker.com/writing-wide-lines-skryf-bree-lyne-gr-1-handwriting-handskrif.pdf
    • http://www.gorillawalker.com/a-textbook-of-oceanography.pdf
    • http://www.gorillawalker.com/west-coast-bering-to-baja.pdf
    • http://www.gorillawalker.com/proactive-customer-service-transforming-your-customer-service-department-into-a.pdf
    • http://www.gorillawalker.com/odin-s-gateways-a-practical-guide-to-the-wisdom-of.pdf
    • http://www.gorillawalker.com/grad-guides-book-3-biological-scis-1995-peterson-s-annual.pdf
    • http://www.gorillawalker.com/i-m-not-broken-i-m-just-different-a-story.pdf
    • http://www.gorillawalker.com/becoming-mentally-tougher-in-triathlons-by-using-meditation-reach-your.pdf
    • http://www.gorillawalker.com/classical-and-contemporary-cryptology.pdf
    • http://www.gorillawalker.com/real-goods-solar-living-source-book-special-30th-anniversary-edition.pdf
    • http://www.gorillawalker.com/snowboarders-start-up-a-beginners-guide-to-snowboarding-start-up.pdf
    • http://www.gorillawalker.com/neurobiological-mechanisms-of-opiate-withdrawal-neuroscience-intelligence-unit.pdf
    • http://www.gorillawalker.com/duo-best-scenes-for-the-90s-applause-acting-series.pdf
    • http://www.gorillawalker.com/the-treasury-of-ancient-egypt.pdf
    • http://www.gorillawalker.com/uae-day-tripper.pdf
    • http://www.gorillawalker.com/effective-training-of-arthroscopic-skills.pdf
    • http://www.gorillawalker.com/earthly-visions-theology-and-the-challenge-of-art-hardback-common.pdf
    • http://www.gorillawalker.com/gould-s-pathophysiology-for-the-health-professions-5e.pdf
    • http://www.gorillawalker.com/never-too-late-willow-creek-book-2-kindle-edition.pdf
    • http://www.gorillawalker.com/caro-s-secrets-of-winning-poker.pdf
    • http://www.gorillawalker.com/assessing-the-open-method-of-coordination-institutional-design-and-national.pdf
    • http://www.gorillawalker.com/the-i-love-trader-joe-s-college-cookbook-150-cheap.pdf
    • http://www.gorillawalker.com/when-movements-anchor-parties-electoral-alignments-in-american-history-princeton.pdf
    • http://www.gorillawalker.com/veterinary-technician-s-manual-for-small-animal-emergency-and-critical.pdf
    • http://www.gorillawalker.com/walt-disney-true-bookgreat-american-business.pdf
    • http://www.gorillawalker.com/needing-me-wanting-you-triple-m-mc-series-volume-4.pdf
    • http://www.gorillawalker.com/build-your-own-polyhedra.pdf
    • http://www.gorillawalker.com/fundamentals-of-franchising.pdf
    • http://www.gorillawalker.com/pharmacy-aide-passbooks-career-examination-passbooks.pdf
    • http://www.gorillawalker.com/the-werewolf-s-lover.pdf
    • http://www.gorillawalker.com/dessins-z.pdf
    • http://www.gorillawalker.com/magnus-hirschfeld-and-the-quest-for-sexual-freedom-a-history.pdf
    • http://www.gorillawalker.com/lecciones-elementales-de-ajedrez-spanish-edition.pdf
    • http://www.gorillawalker.com/life-of-black-hawk-or-ma-ka-tai-me-she.pdf
    • http://www.gorillawalker.com/production-of-virus-free-seed-potatoes-based-on-a-research.pdf
    • http://www.gorillawalker.com/a-comparative-psalter-hebrew-masoretic-text-revised-standard-version-bible.pdf
    • http://www.gorillawalker.com/arts-sciences-pb-american-albums-from-the-collections-of-the.pdf
    • http://www.gorillawalker.com/grad-guid
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/