Malicious PDF — malware analysis report

Static analysis result for SHA-256 3bc066ad9402e2a9…

MALICIOUS

PDF

45.7 KB Created: 2018-11-26 20:09:54 +03:00 Authoring application: Adobe Acrobat 10.1 (via Adobe Acrobat 10.1 Paper Capture Plug-in)
MD5: 06e6cff2f09c9fd81b717fa4af7ddc52 SHA-1: b5142a20579e66914e6515423f2c4849967e209a SHA-256: 3bc066ad9402e2a98834bd67478d9efd48678c39b5ed9b792011ac2e1e9cac1f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The sample is a PDF document that contains a large number of embedded links to external PDF files hosted on the same domain. This behavior is indicative of a link farm, often used for SEO manipulation or to distribute malicious content. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8439

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/undercover-empath-kindred-demon.pdf
    • http://www.gorillawalker.com/the-pirates-of-panama.pdf
    • http://www.gorillawalker.com/how-to-hook-launch-traction-mods-for-street-strip-s.pdf
    • http://www.gorillawalker.com/pizzas-mas-de-100-recetas-para-compartir-en-familia-spanish.pdf
    • http://www.gorillawalker.com/my-heart-will-go-on-love-theme-from-titanic-piano.pdf
    • http://www.gorillawalker.com/lightfall-genealogy-of-a-museum-paul-and-herta-amir-building.pdf
    • http://www.gorillawalker.com/junjo-romantica-volume-5-yaoi-v-5.pdf
    • http://www.gorillawalker.com/the-fencing-master-kindle-edition.pdf
    • http://www.gorillawalker.com/the-darkest-desires-erotic-poetry-freedom-s-soul-the-darkest.pdf
    • http://www.gorillawalker.com/doing-time-online.pdf
    • http://www.gorillawalker.com/streetfinder-west-palm-beach-and-vicinity-rand-mcnally-streetfinder.pdf
    • http://www.gorillawalker.com/mastering-chemistry-for-chemistry-a-molecular-approach-2nd-edition-2nd.pdf
    • http://www.gorillawalker.com/a-companion-to-pablo-neruda-evaluating-neruda-s-poetry-monograf.pdf
    • http://www.gorillawalker.com/platelet-concentrates-to-treat-musculoskeletal-disease-in-horses-clinical-studies.pdf
    • http://www.gorillawalker.com/dreamer-a-prequel-to-the-mongoliad-the-foreworld-saga.pdf
    • http://www.gorillawalker.com/wandering-stars.pdf
    • http://www.gorillawalker.com/la-grandeza-del-cine-mexicano-the-greatness-of-mexican-film.pdf
    • http://www.gorillawalker.com/here-he-comes-again-storybook-lake.pdf
    • http://www.gorillawalker.com/strong-deaf.pdf
    • http://www.gorillawalker.com/daily-devotions-for-advent-2015-living-gospel.pdf
    • http://www.gorillawalker.com/love-feast-the-heart-of-christian-fellowship.pdf
    • http://www.gorillawalker.com/mathematical-methods-for-physicists-a-concise-introduction.pdf
    • http://www.gorillawalker.com/affirming-diversity-the-sociopolitical-context-of-multicultural-education-6th-edition.pdf
    • http://www.gorillawalker.com/crystallography-vol-1-an-outline-of-the-geometrical-properties-of.pdf
    • http://www.gorillawalker.com/java-learn-java-programming-with-ultimate-zero-to-hero-programming.pdf
    • http://www.gorillawalker.com/druid-animal-oracle.pdf
    • http://www.gorillawalker.com/dynamic-responses-of-six-multistory-buildings-during-the-san-fernando.pdf
    • http://www.gorillawalker.com/job-interview-patterns-100-behavioral-interview-questions-and-answers-second.pdf
    • http://www.gorillawalker.com/carbon-markets-an-international-business-guide.pdf
    • http://www.gorillawalker.com/role-of-cyclin-inhibitor-protein-p21-in-the-inhibition-of.pdf
    • http://www.gorillawalker.com/geriatric-psychopharmacology-medical-psychiatry-series.pdf
    • http://www.gorillawalker.com/best-day-of-my-life-american-authors-satb-satb-sheet.pdf
    • http://www.gorillawalker.com/the-kuan-yin-oracle.pdf
    • http://www.gorillawalker.com/minecraft-magic-guide-tc-kindle-edition.pdf
    • http://www.gorillawalker.com/brands-visions-and-values.pdf
    • http://www.gorillawalker.com/across-the-red-river-rwanda-burundi-and-the-heart-of.pdf
    • http://www.gorillawalker.com/american-economic-history-8th-edition-pearson-series-in-economics.pdf
    • http://www.gorillawalker.com/prediction-of-payload-vibration-environments-by-mechanical-admittance-test-techniques.pdf
    • http://www.gorillawalker.com/levana-cooks-dairy-free-natural-and-delicious-recipes-for-your.pdf
    • http://www.gorillawalker.com/rose-paterson-s-illalong-letters-1873-1888.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/