Malicious PDF — malware analysis report

Static analysis result for SHA-256 3edf6c48051631da…

MALICIOUS

PDF

33.5 KB Created: 2019-05-26 11:49:12 +03:00 Authoring application: DVIPSONE 2.2.4 http://www.YandY.com (via Acrobat Distiller 7.0.5 (Windows)) First seen: 2021-06-28
MD5: 6439eacf4c3a858ae2cb5f54afa55d9e SHA-1: 1a02bd064c3d16f15344181a794915b7c57a81d3 SHA-256: 3edf6c48051631da43c59179ca70284ca3538bb1324251daef7a929a70aed87b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. This suggests a tactic to manipulate search engine results or to distribute a large volume of content, potentially malicious. The ML classifier also flagged the document as malicious. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8529

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/brown-v-board-the-landmark-oral-argument-before-the-supreme.pdf In PDF document text
    • http://www.gorillawalker.com/hot-oil-treatment-transgender-and-genderqueer-erotic-romance.pdfIn PDF document text
    • http://www.gorillawalker.com/fluid-mechanics-of-turbomachinery.pdfIn PDF document text
    • http://www.gorillawalker.com/the-path-to-the-berlin-wall-critical-stages-in-the.pdfIn PDF document text
    • http://www.gorillawalker.com/drugs-and-society.pdfIn PDF document text
    • http://www.gorillawalker.com/mother-tongue-essays-in-feminist-psychoanalytic-interpretation.pdfIn PDF document text
    • http://www.gorillawalker.com/idiot-s-guides-the-middle-east-conflict.pdfIn PDF document text
    • http://www.gorillawalker.com/heck-where-the-bad-kids-go.pdfIn PDF document text
    • http://www.gorillawalker.com/short-history-of-the-universe-scientific-american-library.pdfIn PDF document text
    • http://www.gorillawalker.com/the-veggie-spiral-slicer-cookbook-healthy-and-delicious-twists-on.pdfIn PDF document text
    • http://www.gorillawalker.com/metamorphoses-towards-a-materialist-theory-of-becoming.pdfIn PDF document text
    • http://www.gorillawalker.com/taste-of-home-simple-easy-fast-slow-cooker-385-slow.pdfIn PDF document text
    • http://www.gorillawalker.com/rimbaud-a-biography.pdfIn PDF document text
    • http://www.gorillawalker.com/the-elements-of-law-natural-and-politic-to-which-are.pdfIn PDF document text
    • http://www.gorillawalker.com/nicholas-georgiadis-paintings-stage-designs-1955-2001.pdfIn PDF document text
    • http://www.gorillawalker.com/german-american-folklore-a-living-legacy-in-proverbs-riddles-crafts.pdfIn PDF document text
    • http://www.gorillawalker.com/almost-perfect-power-handling-looks-but-it-comes-at-a.pdfIn PDF document text
    • http://www.gorillawalker.com/spectral-theory-function-spaces-and-inequalities-new-techniques-and-recent.pdfIn PDF document text
    • http://www.gorillawalker.com/so-excited-so-scared-the-saved-by-the-bell-retrospective.pdfIn PDF document text
    • http://www.gorillawalker.com/spectrum-reading-grade-2-mcgraw-hill-learning-materials-spectrum.pdfIn PDF document text
    • http://www.gorillawalker.com/early-horror-works.pdfIn PDF document text
    • http://www.gorillawalker.com/globe-touch-uk-s-student-s-guide-tier-4-general.pdfIn PDF document text
    • http://www.gorillawalker.com/strategies-for-protection-and-management-of-floodplain-wetlands-and-other.pdfIn PDF document text
    • http://www.gorillawalker.com/how-to-archive-family-photos-a-step-by-step-guide.pdfIn PDF document text
    • http://www.gorillawalker.com/a-perfect-trip-to-italy-in-the-golden-years-volume.pdfIn PDF document text
    • http://www.gorillawalker.com/earth-s-proximal-space-electric-and-magnetic-environment.pdfIn PDF document text
    • http://www.gorillawalker.com/david-and-me-under-the-sea-essays-from-a-decade.pdfIn PDF document text
    • http://www.gorillawalker.com/case-studies-in-global-health-millions-saved-texts-in-essential.pdfIn PDF document text
    • http://www.gorillawalker.com/rationing-of-cancer-drugs-defies-duty-of-care-focus-an.pdfIn PDF document text
    • http://www.gorillawalker.com/icelandic-histories-romances.pdfIn PDF document text
    • http://www.gorillawalker.com/guicciardini-dialogue-on-the-government-of-florence-cambridge-texts-in.pdfIn PDF document text
    • http://www.gorillawalker.com/freud-his-followers.pdfIn PDF document text
    • http://www.gorillawalker.com/writing-the-classical-way.pdfIn PDF document text
    • http://www.gorillawalker.com/a-vineyard-in-tuscany-illustrated-edition-illustrated-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/cut-snake-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/rising-stars-of-manga-uk-ireland-edition-volume-2-vol.pdfIn PDF document text
    • http://www.gorillawalker.com/how-to-sit-parallax-s-series.pdfIn PDF document text
    • http://www.gorillawalker.com/manuale-dell-imperfetto-sportivo.pdfIn PDF document text
    • http://www.gorillawalker.com/the-economic-assessment-of-mergers-under-european-competition-law-law.pdfIn PDF document text
    • http://www.gorillawalker.com/norway-road-atlas-veiatlas-norge-2009.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://www.YandY.comIn PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text