Malicious PDF — malware analysis report

Static analysis result for SHA-256 356b43db5fb3a95b…

MALICIOUS

PDF

41.4 KB Created: 2018-12-02 10:55:58 +03:00 Authoring application: Adobe Acrobat 6.02 (via Adobe Acrobat 6.02 Paper Capture Plug-in)
MD5: 6450c4bf6753b7522fb754dd11d27152 SHA-1: 24e3269334e22491e90b86686e1a9108aebf4326 SHA-256: 356b43db5fb3a95b221f4f590200a987db096b56352204b8c87aaa0fb32b5145
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded URLs, many of which point to PDFs on the same domain, suggesting a link farm or a method to distribute malicious content. The document body is heavily obfuscated and unreadable, providing no direct clues about its intent. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9027

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/ios-8-sdk-development-creating-iphone-and-ipad-apps-with.pdf
    • http://www.gorillawalker.com/cygnes-flute-et-harpe-ou-piano-composed-by-henri-busser.pdf
    • http://www.gorillawalker.com/immunopathology-of-tropical-diseases.pdf
    • http://www.gorillawalker.com/vanquish-magazine-anz-feb-2014-glamour-entertainment-magazine.pdf
    • http://www.gorillawalker.com/kid-fitness.pdf
    • http://www.gorillawalker.com/fast-walking.pdf
    • http://www.gorillawalker.com/say-it-with-charts.pdf
    • http://www.gorillawalker.com/intertwining.pdf
    • http://www.gorillawalker.com/la-l-gende-tragique-de-jordano-bruno-french-edition.pdf
    • http://www.gorillawalker.com/brian-chippendale-if-n-oof-picturebox-books.pdf
    • http://www.gorillawalker.com/chasing-sylvia-beach.pdf
    • http://www.gorillawalker.com/archie-andrews-drugstore-mixup-and-red-cross-benefit-2-shows.pdf
    • http://www.gorillawalker.com/american-directors.pdf
    • http://www.gorillawalker.com/suckled-by-the-viking-kindle-edition.pdf
    • http://www.gorillawalker.com/dinamika-i-seismostoikost-sooruzhenii-russian-edition.pdf
    • http://www.gorillawalker.com/chaos-catastrophe-and-human-affairs-applications-of-nonlinear-dynamics-to.pdf
    • http://www.gorillawalker.com/the-universal-path-of-natural-life-course-for-total-health.pdf
    • http://www.gorillawalker.com/introducing-fractals-a-graphic-guide-revised-edition-by-lesmoir-gordon.pdf
    • http://www.gorillawalker.com/hex-appeal-kate-daniels.pdf
    • http://www.gorillawalker.com/the-black-border-kindle-edition.pdf
    • http://www.gorillawalker.com/fistful-of-feet-kindle-edition.pdf
    • http://www.gorillawalker.com/breaking-the-mould-picas-series-28.pdf
    • http://www.gorillawalker.com/counseling-african-american-marriages-and-families-counseling-and-pastoral-theology.pdf
    • http://www.gorillawalker.com/understanding-irritable-bowel-syndrome-family-doctor-books.pdf
    • http://www.gorillawalker.com/the-second-oldest-profession-books-1-3.pdf
    • http://www.gorillawalker.com/state-crime-current-perspectives-critical-issues-in-crime-and-society.pdf
    • http://www.gorillawalker.com/mothering-the-new-mother-your-postpartum-resource-companion.pdf
    • http://www.gorillawalker.com/no-limits-brutal-master-series-book-2.pdf
    • http://www.gorillawalker.com/briar-blackwood-s-grimmest-of-fairytales.pdf
    • http://www.gorillawalker.com/waterfalls-of-the-mid-atlantic-states-200-falls-in-maryland.pdf
    • http://www.gorillawalker.com/cuentos-desde-las-sombras-spanish-edition-kindle-edition.pdf
    • http://www.gorillawalker.com/practical-cost-control-handbook-for-project-managers.pdf
    • http://www.gorillawalker.com/a-reader-in-ecclesiology-ashgate-contemporary-ecclesiology.pdf
    • http://www.gorillawalker.com/innovations-for-shape-analysis-models-and-algorithms-mathematics-and-visualization.pdf
    • http://www.gorillawalker.com/train-the-trainer-workshop-coursebook-3rd-edition-w-cd.pdf
    • http://www.gorillawalker.com/a-compilation-of-available-literature-on-the-larvae-of-fishes.pdf
    • http://www.gorillawalker.com/the-boston-italians-a-story-of-pride-perseverance-and-paesani.pdf
    • http://www.gorillawalker.com/owasp-top-10-the-top-10-most-critical-web-application.pdf
    • http://www.gorillawalker.com/on-putnam-wadsworth-philosophers.pdf
    • http://www.gorillawalker.com/intimate.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/