Malicious PDF — malware analysis report

Static analysis result for SHA-256 32314e69b69c3d4c…

MALICIOUS

PDF

44.6 KB Created: 2018-11-23 08:04:50 +03:00 Authoring application: - (via Acrobat Distiller 5.0.1 for Macintosh)
MD5: 73b81e5d77967e7f9749c48d263f3cdb SHA-1: 17a816f138dc288163b724d2fa2ebf5cd509d3c1 SHA-256: 32314e69b69c3d4c3e03f99d106dacd6ea0b6d52bd52428119522f93a5164bb5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier and contains a large number of external links, many of which point to PDF files on the same domain. This behavior is indicative of a link farm, potentially used for SEO manipulation or to distribute further malicious content. The embedded URLs suggest a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9171

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/the-book-of-green-tea.pdf
    • http://www.gorillawalker.com/the-finger-lakes-book-a-complete-guide-great-destinations.pdf
    • http://www.gorillawalker.com/workbook-for-the-esl-writer-s-handbook-pitt-series-in.pdf
    • http://www.gorillawalker.com/english-toefl-toeic-ielts-2500-key-words-interactive-quiz-book.pdf
    • http://www.gorillawalker.com/m-xico-en-la-obra-de-octavio-paz-i-el.pdf
    • http://www.gorillawalker.com/letters-of-a-civil-war-nurse-cornelia-hancock-1863-1865.pdf
    • http://www.gorillawalker.com/english-electric-images-of-england.pdf
    • http://www.gorillawalker.com/pope-john-paul-ii-vatican-city-rome-italy-photo-albums.pdf
    • http://www.gorillawalker.com/skin-game-dark-angel.pdf
    • http://www.gorillawalker.com/alexandra-the-last-tsarina.pdf
    • http://www.gorillawalker.com/molecular-and-cellular-technologies-for-forage-improvement-cssa-special-publication.pdf
    • http://www.gorillawalker.com/a-world-made-for-money-economy-geography-and-the-way.pdf
    • http://www.gorillawalker.com/mending-the-bends-assessment-management-and-recompression-therapy.pdf
    • http://www.gorillawalker.com/development-through-life-a-psychosocial-approach-with-infotrac.pdf
    • http://www.gorillawalker.com/south-africa-unabridged-audible-audio-edition.pdf
    • http://www.gorillawalker.com/shuffle-tracking-for-beginners.pdf
    • http://www.gorillawalker.com/bobby-and-the-soccer-ball-bilingual-english-spanish-with-audio.pdf
    • http://www.gorillawalker.com/the-great-god-pan-xelucha.pdf
    • http://www.gorillawalker.com/applied-multiple-regression-correlation-analysis-for-the-behavioral-sciences.pdf
    • http://www.gorillawalker.com/natural-history-of-american-birds-of-eastern-and-central-north.pdf
    • http://www.gorillawalker.com/el-problema-es-usted-c.pdf
    • http://www.gorillawalker.com/wind-power-energy-now-in-the-future.pdf
    • http://www.gorillawalker.com/101-montunos-english-and-spanish-edition.pdf
    • http://www.gorillawalker.com/artillery-war-machines.pdf
    • http://www.gorillawalker.com/faith-hill-rlr-oop-real-life-reader-biography.pdf
    • http://www.gorillawalker.com/the-secret-diary-of-ewan-macrae.pdf
    • http://www.gorillawalker.com/efficient-aviation-security-strengthening-the-analytic-foundation-for-making-air.pdf
    • http://www.gorillawalker.com/sd-card-projects-using-the-pic-microcontroller.pdf
    • http://www.gorillawalker.com/laughter-is-the-best-medicine.pdf
    • http://www.gorillawalker.com/dances-with-waves-around-ireland-by-kayak-another-ireland-by.pdf
    • http://www.gorillawalker.com/beautiful-soccer-creating-passion-and-confidence-in-young-players-kindle.pdf
    • http://www.gorillawalker.com/introduction-to-cardiovascular-nursing.pdf
    • http://www.gorillawalker.com/savvy-girl-a-guide-to-etiquette-volume-2.pdf
    • http://www.gorillawalker.com/current-diagnosis-treatment-of-pain-lange-current-series.pdf
    • http://www.gorillawalker.com/the-psychology-of-personhood-philosophical-historical-social-developmental-and-narrative.pdf
    • http://www.gorillawalker.com/time-management-the-stress-free-strategies-how-to-get-more.pdf
    • http://www.gorillawalker.com/feed-marketing-in-ethiopia-results-of-rapid-market-appraisal.pdf
    • http://www.gorillawalker.com/binary-gaseous-liquid-near-critical-and-supercritical-fluid-systems-of.pdf
    • http://www.gorillawalker.com/sampling-of-populations-methods-and-applications.pdf
    • http://www.gorillawalker.com/scientists-greater-than-einstein-the-biggest-lifesavers-of-the-twentieth.pdf
    • http://www.gorillawalker.com/pope-john-paul-ii-vatican-city-rome-italy-pho
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/