Malicious PDF — malware analysis report

Static analysis result for SHA-256 3d9b28dcdb59803d…

MALICIOUS

PDF

44.2 KB Created: 2019-03-17 01:52:29 +03:00 Authoring application: FrameMaker 7.0 (via Acrobat Distiller 5.0.5 (Windows); modified using iText® 5.5.4 ©2000-2014 iText Group NV (AGPL-version)) First seen: 2020-12-25
MD5: f4e175c31e76fb960bb893682f7e85be SHA-1: 9c2d1cca64eb7e55a0f92ce60b368b9bc0d4c0e9 SHA-256: 3d9b28dcdb59803dc51380c91be85f47dae0edbf0258619df9bb45ade8fd422a
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files hosted on the same domain. This is indicative of a link farm, often used for SEO manipulation or to distribute further malicious content. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8439

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/god-was-in-this-place-i-i-did-not-know.pdf In PDF document text
    • http://www.gorillawalker.com/oxford-reading-tree-level-1-floppy-s-phonics-pack-of.pdfIn PDF document text
    • http://www.gorillawalker.com/psychological-testing-and-assessment-an-introduction-to-tests-measurement-8th.pdfIn PDF document text
    • http://www.gorillawalker.com/machine-transcription-for-document-processing.pdfIn PDF document text
    • http://www.gorillawalker.com/owning-russia-the-struggle-over-factories-farms-and-power-hardcover.pdfIn PDF document text
    • http://www.gorillawalker.com/clara-barton-face-danger-but-never-fear-it-americans-the.pdfIn PDF document text
    • http://www.gorillawalker.com/justification-and-critique-towards-a-critical-theory-of-politics.pdfIn PDF document text
    • http://www.gorillawalker.com/the-love-letters-of-dylan-thomas.pdfIn PDF document text
    • http://www.gorillawalker.com/auto-responders-abcs-the-ultimate-guide-to-email-marketing-and.pdfIn PDF document text
    • http://www.gorillawalker.com/china-world-cultures-through-time-primary-source-readers.pdfIn PDF document text
    • http://www.gorillawalker.com/exactly-the-opposite.pdfIn PDF document text
    • http://www.gorillawalker.com/infinite-abelian-groups-volume-2.pdfIn PDF document text
    • http://www.gorillawalker.com/making-magic-how-orlando-won-an-nba-team.pdfIn PDF document text
    • http://www.gorillawalker.com/philip-s-atlas-of-universe-pb-tsp.pdfIn PDF document text
    • http://www.gorillawalker.com/critical-companion-to-tim-o-brien.pdfIn PDF document text
    • http://www.gorillawalker.com/welder-s-handbook-revisedhp1513-a-guide-to-plasma-cutting-oxyacetylene.pdfIn PDF document text
    • http://www.gorillawalker.com/marketing-w-student-cd-rom-and-powerweb.pdfIn PDF document text
    • http://www.gorillawalker.com/flip-outside-the-box-creative-women-s-gymnastics-elements.pdfIn PDF document text
    • http://www.gorillawalker.com/occidentalism-a-theory-of-counter-discourse-in-post-mao-china.pdfIn PDF document text
    • http://www.gorillawalker.com/hellig-olaf-historisk-fort-lling-norwegian-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/out-of-left-field-marlee-s-story.pdfIn PDF document text
    • http://www.gorillawalker.com/wordly-wise-book-8.pdfIn PDF document text
    • http://www.gorillawalker.com/mems-introduction-and-fundamentals-mechanical-and-aerospace-engineering-series.pdfIn PDF document text
    • http://www.gorillawalker.com/women-scientists-in-america-forging-a-new-world-since-1972.pdfIn PDF document text
    • http://www.gorillawalker.com/your-best-child-ever-is-this-game-worth-winning-how.pdfIn PDF document text
    • http://www.gorillawalker.com/the-practice-slave-stories-of-domination-and-submission.pdfIn PDF document text
    • http://www.gorillawalker.com/sketchup-for-interior-design-3d-visualizing-designing-and-space-planning.pdfIn PDF document text
    • http://www.gorillawalker.com/103-chistes-comiqu.pdfIn PDF document text
    • http://www.gorillawalker.com/engineering-design-graphics-with-solidworks-2011-1st-first-edition-by.pdfIn PDF document text
    • http://www.gorillawalker.com/ipt-s-guide-to-blueprint-interpretation.pdfIn PDF document text
    • http://www.gorillawalker.com/softball-skills-drills-2nd-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/here-s-ireland.pdfIn PDF document text
    • http://www.gorillawalker.com/albuquerque-diy-city-guide-and-travel-journal-city-notebook-for.pdfIn PDF document text
    • http://www.gorillawalker.com/bounce-roll-fly-the-science-of-balls-volume-6-data.pdfIn PDF document text
    • http://www.gorillawalker.com/collins-scrabble-dictionary.pdfIn PDF document text
    • http://www.gorillawalker.com/mj-the-genius-of-michael-jackson.pdfIn PDF document text
    • http://www.gorillawalker.com/intelligent-memory-systems-second-international-workshop-ims-2000-cambridge-ma.pdfIn PDF document text
    • http://www.gorillawalker.com/living-with-lupus-women-and-chronic-illness-in-ecuador-louann.pdfIn PDF document text
    • http://www.gorillawalker.com/operation-love-match-svh-103-sweet-valley-high.pdfIn PDF document text
    • http://www.gorillawalker.com/electricity-industry-and-class-in-south-africa-st-antony-s.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text