Malicious PDF — malware analysis report

Static analysis result for SHA-256 51219f1b9f694f22…

MALICIOUS

PDF

33.2 KB Created: 2019-08-03 20:42:19 +03:00 Authoring application: Writer (via OpenOffice.org 1.1.2) First seen: 2021-06-28
MD5: ce3edba7c18ebca03758ea7aaa536199 SHA-1: c10e555219c26b9a8a955d3460cfaab90189a3ec SHA-256: 51219f1b9f694f22a70600d9af8a82b5654e114de41d664f05b70f3a32044970
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF was flagged by a machine learning classifier and a critical heuristic for containing a large number of external links, suggesting a link farm or content distribution tactic. The embedded URLs point to various PDF documents hosted on the same domain, indicating a coordinated effort to direct users to specific content. No scripts were extracted, and the document body was unreadable, limiting further analysis of the immediate intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8529

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/your-5-minute-personal-coach-ask-the-right-questions-get.pdf In PDF document text
    • http://www.gorillawalker.com/own-me-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/travellers-mauritius-travellers-thomas-cook.pdfIn PDF document text
    • http://www.gorillawalker.com/lessing-laocoonte-laocoon-o-sobre-los-limites-de-la-pintura.pdfIn PDF document text
    • http://www.gorillawalker.com/homes-first-discoveries.pdfIn PDF document text
    • http://www.gorillawalker.com/thomas-pfau-romantic-moods-paranoia-trauma-and-melancholy-1790-1840.pdfIn PDF document text
    • http://www.gorillawalker.com/human-from-another-outlook.pdfIn PDF document text
    • http://www.gorillawalker.com/sacr-small-animal-orthopedics-98.pdfIn PDF document text
    • http://www.gorillawalker.com/first-book-of-the-piano-usborne-first-music.pdfIn PDF document text
    • http://www.gorillawalker.com/beacon-bible-commentary-volume-5-hosea-through-malachi-beacon-commentary.pdfIn PDF document text
    • http://www.gorillawalker.com/the-waiting-list-an-iraqi-woman-s-tales-of-alienation.pdfIn PDF document text
    • http://www.gorillawalker.com/aces-and-eights-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/keeper-n-me.pdfIn PDF document text
    • http://www.gorillawalker.com/op-ghost-towns-werewolf-the-apocalypse.pdfIn PDF document text
    • http://www.gorillawalker.com/replays-using-play-to-enhance-emotional-and-behavioral-development-for.pdfIn PDF document text
    • http://www.gorillawalker.com/annual-review-of-nursing-research-volume-7-1989-focus-on.pdfIn PDF document text
    • http://www.gorillawalker.com/wasted-a-memoir-of-anorexia-and-bulimia.pdfIn PDF document text
    • http://www.gorillawalker.com/quiet-bunny-s-many-colors.pdfIn PDF document text
    • http://www.gorillawalker.com/louisiana-millionaire.pdfIn PDF document text
    • http://www.gorillawalker.com/product-design-now.pdfIn PDF document text
    • http://www.gorillawalker.com/the-past-that-might-have-been-the-future-that-may.pdfIn PDF document text
    • http://www.gorillawalker.com/theater-and-film-a-comparative-anthology.pdfIn PDF document text
    • http://www.gorillawalker.com/feathered-dragons-studies-on-the-transition-from-dinosaurs-to-birds.pdfIn PDF document text
    • http://www.gorillawalker.com/the-owl-and-the-pussycat-went-to-see-libretto-acting.pdfIn PDF document text
    • http://www.gorillawalker.com/spelling-workout-level-c.pdfIn PDF document text
    • http://www.gorillawalker.com/heading-towards-extinction-indigenous-rights-in-africa-the-case-of.pdfIn PDF document text
    • http://www.gorillawalker.com/dangerous-and-deadly-weapons-i-d-guide.pdfIn PDF document text
    • http://www.gorillawalker.com/human-ecology.pdfIn PDF document text
    • http://www.gorillawalker.com/introduction-to-jaguar-parts-training-module-introduction-to-jaguar-self.pdfIn PDF document text
    • http://www.gorillawalker.com/modern-weapons-and-warfare-the-technology-of-war-from-1700.pdfIn PDF document text
    • http://www.gorillawalker.com/close-up-b1-student-s-book.pdfIn PDF document text
    • http://www.gorillawalker.com/night-light-a-book-of-nighttime-meditations-hazelden-meditation-series.pdfIn PDF document text
    • http://www.gorillawalker.com/the-cloud-of-unknowing-and-other-treatises-the-epistle-of.pdfIn PDF document text
    • http://www.gorillawalker.com/mirrors-messages-manifestations-aperture-monograph.pdfIn PDF document text
    • http://www.gorillawalker.com/my-little-toolbox.pdfIn PDF document text
    • http://www.gorillawalker.com/forget-foucault-semiotext-e-foreign-agents.pdfIn PDF document text
    • http://www.gorillawalker.com/precalculus-concepts-through-functions-a-unit-circle-approach-to-trigonometry.pdfIn PDF document text
    • http://www.gorillawalker.com/insight-compact-guide-florence-florence-1998.pdfIn PDF document text
    • http://www.gorillawalker.com/learn-to-draw-disney-s-enchanted-princesses-drawing-book-kit.pdfIn PDF document text
    • http://www.gorillawalker.com/military-and-government-technology-raintree-freestyle.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text