Malicious PDF — malware analysis report

Static analysis result for SHA-256 42966fd7511a5274…

MALICIOUS

PDF

45.2 KB Created: 2019-01-06 08:14:43 +03:00 Authoring application: Adobe InDesign CS (3.0) (via Adobe PDF Library 6.0)
MD5: 3b8983978e10a11b3e74d3e225e6fa6b SHA-1: 165dfeac441a296dcf8286edb88edb7005cbbd18 SHA-256: 42966fd7511a5274c6d865a1d1af83e44b6273c7071e47ff2298550b8dc64434
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a large external link farm, pointing to 32 PDF files on the domain www.gorillawalker.com. The document body also contains numerous URLs pointing to PDF files on the same domain. This suggests the primary purpose is to direct users to these external resources, likely for SEO manipulation or as a distribution vector for other malicious content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/geaux-tigers-activity-book-and-app.pdf
    • http://www.gorillawalker.com/the-chronic-pain-care-workbook-a-self-treatment-approach-to.pdf
    • http://www.gorillawalker.com/taxi-c.pdf
    • http://www.gorillawalker.com/corrections-the-fundamentals.pdf
    • http://www.gorillawalker.com/six-suspects-a-novel.pdf
    • http://www.gorillawalker.com/sing-spell-read-write-raceway-book-intensive-systematic-phonics-vocabulary.pdf
    • http://www.gorillawalker.com/become-a-critical-reader-an-article-from-journal-of-dental.pdf
    • http://www.gorillawalker.com/250-utah-dmv-practice-test-questions-kindle-edition.pdf
    • http://www.gorillawalker.com/the-monkey-people-a-colombian-folktale-rabbit-ears-we-all.pdf
    • http://www.gorillawalker.com/undersea.pdf
    • http://www.gorillawalker.com/symphony-in-b-flat-major-for-concert-band-bassoon-i.pdf
    • http://www.gorillawalker.com/following-the-rules-practical-reasoning-and-deontic-constraint.pdf
    • http://www.gorillawalker.com/vitamin-c-serum-for-healthier-skin-how-to-make-and.pdf
    • http://www.gorillawalker.com/what-is-scientology.pdf
    • http://www.gorillawalker.com/salafi-jihadi-discourse-of-sunni-islam-in-the-21st-century.pdf
    • http://www.gorillawalker.com/test-best-itbs-test-workbook-grade-8-level-14.pdf
    • http://www.gorillawalker.com/american-red-cross-babysitter-s-training-handbook.pdf
    • http://www.gorillawalker.com/a-walkable-feast-exploring-hemingway-s-paris-on-foot.pdf
    • http://www.gorillawalker.com/spatial-mathematics-theory-and-practice-through-mapping-hardcover.pdf
    • http://www.gorillawalker.com/understanding-the-male-temperament-what-every-man-would-like-to.pdf
    • http://www.gorillawalker.com/journey-to-the-source-of-the-river-oxus.pdf
    • http://www.gorillawalker.com/the-uncanonical-and-apocryphal-scriptures.pdf
    • http://www.gorillawalker.com/find-out-about-native-americans-what-life-was-like-for.pdf
    • http://www.gorillawalker.com/ceserani-and-kinton-s-the-theory-of-catering.pdf
    • http://www.gorillawalker.com/pocket-guide-to-trading-online-put-your-money-where-your.pdf
    • http://www.gorillawalker.com/winds-of-change-book-two.pdf
    • http://www.gorillawalker.com/hiking-and-backpacking-santa-barbara-and-ventura.pdf
    • http://www.gorillawalker.com/kids-love-i-95-2nd-edition-your-family-travel-guide.pdf
    • http://www.gorillawalker.com/frog-unabridged-audible-audio-edition.pdf
    • http://www.gorillawalker.com/woken.pdf
    • http://www.gorillawalker.com/unix-shells-by-example.pdf
    • http://www.gorillawalker.com/les-miserables-classics-illustrated.pdf
    • http://www.gorillawalker.com/onions-webster-s-quotations-facts-and-phrases.pdf
    • http://www.gorillawalker.com/activities-manual-for-electric-motors-and-control-systems-w-constructor.pdf
    • http://www.gorillawalker.com/analytics-and-modern-warfare-dominance-by-the-numbers.pdf
    • http://www.gorillawalker.com/the-bookshop-strikes-back.pdf
    • http://www.gorillawalker.com/women-exclusive-wall-calendar-2016-adult-calendar-nude-calendar-erotic.pdf
    • http://www.gorillawalker.com/civics-flash-cards-for-the-new-naturalization-test-2009.pdf
    • http://www.gorillawalker.com/stuff-every-groom-should-know.pdf
    • http://www.gorillawalker.com/polytomography-of-the-temporal-bone-modern-concepts-of-radiology-nuclear.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/