Malicious PDF — malware analysis report

Static analysis result for SHA-256 471a377fb077429f…

MALICIOUS

PDF

33.3 KB Created: 2019-12-13 19:09:38 +03:00 Authoring application: Microsoft Word (via Acrobat PDFWriter 4.05 for Windows NT) First seen: 2021-06-28
MD5: a60dbcede80c27b5e397a6cf06cda176 SHA-1: f2abe65d9f49487d50a2bce1574f6b7c0e08bacf SHA-256: 471a377fb077429f75cd53a5fd981b5d9d9b1f6f544e16ee6aff9c5835aec6b3
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. This suggests the document's primary purpose is to act as a link farm, potentially for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8529

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/pilgrim-stories-on-and-off-the-road-to-santiago-journeys.pdf In PDF document text
    • http://www.gorillawalker.com/the-chaucer-story-book-illustrated-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/great-western-kings-haynes-great-locomotives.pdfIn PDF document text
    • http://www.gorillawalker.com/change-the-world-change-your-life-discover-your-life-purpose.pdfIn PDF document text
    • http://www.gorillawalker.com/mechanical-appliances-mechanical-movements-and-novelties-of-construction.pdfIn PDF document text
    • http://www.gorillawalker.com/we-shall-see-the-king.pdfIn PDF document text
    • http://www.gorillawalker.com/birds-of-oregon-field-guide.pdfIn PDF document text
    • http://www.gorillawalker.com/amazon-echo-the-complete-user-guide-echo-amazon-echo-user.pdfIn PDF document text
    • http://www.gorillawalker.com/heuristic-search-theory-and-applications.pdfIn PDF document text
    • http://www.gorillawalker.com/nothing-to-say-and-saying-it-poems.pdfIn PDF document text
    • http://www.gorillawalker.com/us-army-technical-manual-tm-5-3740-206-24p-sprayer.pdfIn PDF document text
    • http://www.gorillawalker.com/stink-and-the-incredible-super-galactic-jawbreaker.pdfIn PDF document text
    • http://www.gorillawalker.com/village-pumps-shire-library.pdfIn PDF document text
    • http://www.gorillawalker.com/cancer-as-initiation-surviving-the-fire-dreamcatcher.pdfIn PDF document text
    • http://www.gorillawalker.com/has-jack-the-ripper-told-you-chaps-what-his-real.pdfIn PDF document text
    • http://www.gorillawalker.com/buttercups-and-strong-boys-penguin-sports-library.pdfIn PDF document text
    • http://www.gorillawalker.com/charlie-chaplin-a-brief-life-ackroyd-s-brief-lives.pdfIn PDF document text
    • http://www.gorillawalker.com/women-s-dermatology-an-issue-of-dermatologic-clinics-1e-the.pdfIn PDF document text
    • http://www.gorillawalker.com/a-virgin-conceived-mary-and-classical-representations-of-virginity-book.pdfIn PDF document text
    • http://www.gorillawalker.com/dr-donsbach-tells-you-menopause-hysterectomy-what-you-always-wanted.pdfIn PDF document text
    • http://www.gorillawalker.com/thomas-cook-european-rail-timetable-independent-traveller-s-spring-timetable.pdfIn PDF document text
    • http://www.gorillawalker.com/this-is-the-way-we-go-to-school-scholastic-news.pdfIn PDF document text
    • http://www.gorillawalker.com/stones-and-cord-in-glass.pdfIn PDF document text
    • http://www.gorillawalker.com/nigeria-company-laws-and-regulations-handbook-world-law-business-library.pdfIn PDF document text
    • http://www.gorillawalker.com/the-mermaids-singing-tony-hill-carol-jordan.pdfIn PDF document text
    • http://www.gorillawalker.com/the-sciences-of-homosexuality-in-early-modern-europe.pdfIn PDF document text
    • http://www.gorillawalker.com/people-in-high-places-approaches-to-tibet.pdfIn PDF document text
    • http://www.gorillawalker.com/my-birthday-album-my-photography.pdfIn PDF document text
    • http://www.gorillawalker.com/double-team-teenage-mutant-ninja-turtles-step-into-reading.pdfIn PDF document text
    • http://www.gorillawalker.com/the-other-guy-blinked-and-other-dispatches-from-the-cola.pdfIn PDF document text
    • http://www.gorillawalker.com/the-grownup-a-story-by-the-author-of-gone-girl.pdfIn PDF document text
    • http://www.gorillawalker.com/stranded-mated-on-the-tentacle-planet-steamy-sci-fi-tentacle.pdfIn PDF document text
    • http://www.gorillawalker.com/focus-on-grammar-2-an-integrated-skills-approach-third-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/morocco-that-was.pdfIn PDF document text
    • http://www.gorillawalker.com/mexico-under-fire-being-the-diary-of-samuel-ryan-curtis.pdfIn PDF document text
    • http://www.gorillawalker.com/transgender-beauty-queen.pdfIn PDF document text
    • http://www.gorillawalker.com/introducing-psychology-a-graphic-guide-introducing-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/researching-power-elites-and-leadership.pdfIn PDF document text
    • http://www.gorillawalker.com/king-solomon-s-ring-new-light-on-animal-ways.pdfIn PDF document text
    • http://www.gorillawalker.com/life-under-the-eastern-sky.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text