Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ee5087c97daa6d4…

MALICIOUS

PDF

34.1 KB Created: 2019-07-01 18:05:36 +03:00 Authoring application: Adobe Acrobat Pro 11.0.0 First seen: 2021-06-28
MD5: 565e649ea82dc2162955176fb1e040ef SHA-1: 201c261262e2e88d6d440e6d6679e811ac681ec8 SHA-256: 4ee5087c97daa6d48dc1a49974ddb9ae996db372b809590cb24eeefbee910229
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to other PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. This suggests a tactic to manipulate search engine results or to serve as a distribution point for further malicious content. No scripts were extracted, and the document body was unreadable, limiting further analysis.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8313

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/fundamentals-of-ocean-acoustics-springer-series-in-electronics-and-photonics.pdf In PDF document text
    • http://www.gorillawalker.com/cooking-for-today-pasta.pdfIn PDF document text
    • http://www.gorillawalker.com/computer-aided-reasoning-acl2-case-studies-advances-in-formal-methods.pdfIn PDF document text
    • http://www.gorillawalker.com/soft-computing-applications-proceedings-of-the-6th-international-workshop-soft.pdfIn PDF document text
    • http://www.gorillawalker.com/archimate-2-1-specification.pdfIn PDF document text
    • http://www.gorillawalker.com/historia-del-imperio-romano-spanish-edition-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/foundations-of-addictions-counseling-3rd-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/fork-in-the-trail-mouthwatering-meals-and-tempting-treats-for.pdfIn PDF document text
    • http://www.gorillawalker.com/using-mis-student-value-edition-6th-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/2012-wilderness-adventures-calendar.pdfIn PDF document text
    • http://www.gorillawalker.com/the-cello-suites-j-s-bach-pablo-casals-and-the.pdfIn PDF document text
    • http://www.gorillawalker.com/mosquito-control-in-panama-the-eradication-of-malaria-and-yellow.pdfIn PDF document text
    • http://www.gorillawalker.com/freedom-song-the-story-of-henry-box-brown.pdfIn PDF document text
    • http://www.gorillawalker.com/linear-operators-set.pdfIn PDF document text
    • http://www.gorillawalker.com/the-darfur-sultanate-a-history-columbia-hurst.pdfIn PDF document text
    • http://www.gorillawalker.com/a-slave-auction.pdfIn PDF document text
    • http://www.gorillawalker.com/varga-kachina-skyhawk-manners-t-34-looks-rent-an-ex.pdfIn PDF document text
    • http://www.gorillawalker.com/how-to-invest-50-5-000-the-small-investor-s.pdfIn PDF document text
    • http://www.gorillawalker.com/an-innocent-man-s-death-the-story-of-vincent-carnell.pdfIn PDF document text
    • http://www.gorillawalker.com/stuff-good-bass-players-should-know-bk-cd.pdfIn PDF document text
    • http://www.gorillawalker.com/battles-in-the-alps-a-history-of-the-italian-front.pdfIn PDF document text
    • http://www.gorillawalker.com/what-s-mine-is-yours-a-wife-sharing-romance.pdfIn PDF document text
    • http://www.gorillawalker.com/your-drug-may-be-your-problem-how-and-why-to.pdfIn PDF document text
    • http://www.gorillawalker.com/yuletide-stalker-yuletide-series-book-2-steeple-hill-love-inspired.pdfIn PDF document text
    • http://www.gorillawalker.com/bringing-zion-home-israel-in-american-jewish-culture-1948-1967.pdfIn PDF document text
    • http://www.gorillawalker.com/the-emperor-downfall-of-an-autocrat.pdfIn PDF document text
    • http://www.gorillawalker.com/transport-phenomena-in-porous-media-ii-pt-2-1st-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/my-name-is-not-slow-youth-with-mental-retardation-youth.pdfIn PDF document text
    • http://www.gorillawalker.com/gestion-estrategica-y-creacion-de-valor-en-el-sector-publico.pdfIn PDF document text
    • http://www.gorillawalker.com/at-the-zoo-telling-time-by-the-quarter-hour-i.pdfIn PDF document text
    • http://www.gorillawalker.com/a-light-touch-successful-painting-in-oils.pdfIn PDF document text
    • http://www.gorillawalker.com/abraham-cruzvillegas-the-hyundai-commission.pdfIn PDF document text
    • http://www.gorillawalker.com/gis-fundamentals-a-first-text-on-geographic-information-systems-3rd.pdfIn PDF document text
    • http://www.gorillawalker.com/northern-lights.pdfIn PDF document text
    • http://www.gorillawalker.com/the-tobacco-atlas-french-3e.pdfIn PDF document text
    • http://www.gorillawalker.com/s-fuerte-staying-strong-365-d-as-al-a-o.pdfIn PDF document text
    • http://www.gorillawalker.com/hand-trauma-a-practical-guide.pdfIn PDF document text
    • http://www.gorillawalker.com/the-new-yankee-workshop-outdoor-projects.pdfIn PDF document text
    • http://www.gorillawalker.com/perfiditas-roma-nova-book-2-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/o-connor-viola-method-book-1-viola-part-cd.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text