Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ed8ec52a05d7dbb…

MALICIOUS

PDF

41.8 KB Created: 2018-11-26 20:07:06 +03:00 Authoring application: Adobe Illustrator CS3 (via Adobe PDF library 8.00)
MD5: b480bee38bf28da7dd7670b7dc4574e4 SHA-1: 03bb0be0570ee2098129f64f21639916991eb922 SHA-256: 4ed8ec52a05d7dbb5c4e0e5a51e0e17ac34b22e0b82c90b4ea0226fa57cb0fb8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to external PDF files on the same domain, as indicated by the PDF_SEO_LINK_FARM heuristic. This suggests a tactic to manipulate search engine results or to distribute a large volume of content, potentially malicious. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8872

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/heart-of-the-ocean.pdf
    • http://www.gorillawalker.com/practical-radiographic-imaging.pdf
    • http://www.gorillawalker.com/andy-warhol-portraits.pdf
    • http://www.gorillawalker.com/boys-at-war-men-at-peace-former-enemy-air-combatants.pdf
    • http://www.gorillawalker.com/the-bride-next-door-mills-boon-love-inspired-historical-texas.pdf
    • http://www.gorillawalker.com/apple-pro-training-series-xsan-quick-reference-guide-2nd-edition.pdf
    • http://www.gorillawalker.com/outies-mote-series-book-3.pdf
    • http://www.gorillawalker.com/stardom-industry-of-desire.pdf
    • http://www.gorillawalker.com/sadie-s-mate-space-wars-book-2.pdf
    • http://www.gorillawalker.com/world-film-locations-marseilles-intellect-books-world-film-locations.pdf
    • http://www.gorillawalker.com/buenos-aires-the-pampas-footprint-focus.pdf
    • http://www.gorillawalker.com/catalyst-in-the-wake-of-the-great-bhola-cyclone-kindle.pdf
    • http://www.gorillawalker.com/videofluoroscopy-a-multidisciplinary-team-approach.pdf
    • http://www.gorillawalker.com/beginning-nfc-near-field-communication-with-arduino-android-and-phonegap.pdf
    • http://www.gorillawalker.com/aaa-essential-thailand-aaa-essential-guides-thailand.pdf
    • http://www.gorillawalker.com/sauerkraut-suspenders-and-the-swiss-a-political-history-of-green.pdf
    • http://www.gorillawalker.com/authentic-calypso-the-song-the-music-the-dance.pdf
    • http://www.gorillawalker.com/a-guide-book-of-morgan-silver-dollars-official-red-book.pdf
    • http://www.gorillawalker.com/the-top-100-formula-one-drivers-of-all-time.pdf
    • http://www.gorillawalker.com/interviewing-for-a-network-engineer-position-volume-1.pdf
    • http://www.gorillawalker.com/backhoe-loaders-big-backhoe-loaders-digging-dirt-on-the-jobsite.pdf
    • http://www.gorillawalker.com/skiing-for-beginners-types-equipment-techniques-book.pdf
    • http://www.gorillawalker.com/petroleum-refining-technology-and-economics-fifth-edition.pdf
    • http://www.gorillawalker.com/what-did-i-do-the-unauthorized-autobiography-of-larry-rivers.pdf
    • http://www.gorillawalker.com/neuroradiology-key-differential-diagnoses-and-clinical-questions-expert-consult-online.pdf
    • http://www.gorillawalker.com/lidia-s-italian-table-more-than-200-recipes-from-the.pdf
    • http://www.gorillawalker.com/times-food-guide-pune-2014.pdf
    • http://www.gorillawalker.com/slapping-techniques-complete-electric-bass-player.pdf
    • http://www.gorillawalker.com/oregon-history-student-workbook-volume-1.pdf
    • http://www.gorillawalker.com/savard-lee-international-symposium-on-bath-smelting.pdf
    • http://www.gorillawalker.com/jay-z-turtleback-school-library-binding-edition-hip-hop-biographies.pdf
    • http://www.gorillawalker.com/canadian-legal-education-annual-review-2009.pdf
    • http://www.gorillawalker.com/london-walks-and-sightseeing-shakespeare-and-others-on-the-south.pdf
    • http://www.gorillawalker.com/inquiry-into-life-laboratory-manual-12th-edition-special-edition-for.pdf
    • http://www.gorillawalker.com/allgemeine-anleitung-zur-berechnung-der-leibrenten-und-anwartschaften-volume-2.pdf
    • http://www.gorillawalker.com/the-storm-seal.pdf
    • http://www.gorillawalker.com/nos-tomamos-la-palabra-spanish-edition.pdf
    • http://www.gorillawalker.com/the-rough-guide-to-ultimate-musical-adventures-music-rough-guides.pdf
    • http://www.gorillawalker.com/the-origin-of-species-by-means-of-natural-selection-or.pdf
    • http://www.gorillawalker.com/fodor-s-guide-to-south-america-1968.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/