Malicious PDF — malware analysis report

Static analysis result for SHA-256 55e6f3f9136e5ef0…

MALICIOUS

PDF

44.0 KB Created: 2018-11-14 11:22:45 +03:00 Authoring application: Writer (via LibreOffice 4.2)
MD5: bb3d3512dce049d177afffbf76ee1195 SHA-1: 69c7a30b8a50dd1a78f2a9abebf74f8d7a781bb2 SHA-256: 55e6f3f9136e5ef07678cc741b781d1a33fe3ce1df6dd6681708742c10747de7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded URLs, specifically 32, pointing to various PDF documents on the 'gorillawalker.com' domain. This behavior is indicative of a link farm, likely intended to manipulate search engine rankings or to serve as a distribution point for further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9007

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/a-taoist-miscellany.pdf
    • http://www.gorillawalker.com/perry-s-department-store-a-buying-simulation-for-junior-s.pdf
    • http://www.gorillawalker.com/zombie-inc.pdf
    • http://www.gorillawalker.com/creating-a-photo-book-for-seniors-computer-books-for-seniors.pdf
    • http://www.gorillawalker.com/economic-anthropology-a-study-in-comparative-economics.pdf
    • http://www.gorillawalker.com/the-business-analysts-s-handbook-kindle-edition.pdf
    • http://www.gorillawalker.com/building-safety-commitment.pdf
    • http://www.gorillawalker.com/gold-coins-of-the-charlotte-mint-1838-1861-3rd-edition.pdf
    • http://www.gorillawalker.com/the-research-process.pdf
    • http://www.gorillawalker.com/electromagnetic-devices.pdf
    • http://www.gorillawalker.com/introduction-to-human-factors-engineering-pearson-new-international-edition.pdf
    • http://www.gorillawalker.com/l-vangile-selon-la-compagne-bien-aim-e-l-vangile.pdf
    • http://www.gorillawalker.com/hometown-beer-a-history-of-kansas-city-s-breweries.pdf
    • http://www.gorillawalker.com/a-friendly-kill.pdf
    • http://www.gorillawalker.com/the-20th-century-children-s-poetry-treasury-treasured-gifts-for.pdf
    • http://www.gorillawalker.com/how-to-crush-it-on-amazon-create-a-brand-and.pdf
    • http://www.gorillawalker.com/tradition-democracy-and-the-townscape-of-kyoto-claiming-a-right.pdf
    • http://www.gorillawalker.com/the-doctrine-of-scriptural-temperance-an-apology-for-the-doctrine.pdf
    • http://www.gorillawalker.com/basic-clinical-pharmacology-ninth-edition.pdf
    • http://www.gorillawalker.com/peter-hujar-love-lust.pdf
    • http://www.gorillawalker.com/the-mountain-nature-of-things-book-one-a-smoky-mountain.pdf
    • http://www.gorillawalker.com/infinite-sequences-and-series-dover-books-on-mathematics.pdf
    • http://www.gorillawalker.com/harcourt-social-studies-assessment-program-grade-1.pdf
    • http://www.gorillawalker.com/the-body-in-the-bouillon-a-faith-fairchild-mystery.pdf
    • http://www.gorillawalker.com/marvelous-marine-life-coloring-book-art-filled-fun-coloring-books.pdf
    • http://www.gorillawalker.com/the-essential-batman-encyclopedia.pdf
    • http://www.gorillawalker.com/success-principles-to-guide-your-low-carb-diet-supplements-online.pdf
    • http://www.gorillawalker.com/metalheart.pdf
    • http://www.gorillawalker.com/qgis-by-example.pdf
    • http://www.gorillawalker.com/manual-de-acordes-para-guitarra.pdf
    • http://www.gorillawalker.com/an-introduction-to-judaism-introduction-to-religion.pdf
    • http://www.gorillawalker.com/an-itinerary-vvritten-by-fynes-moryson-gent-first-in-the.pdf
    • http://www.gorillawalker.com/mao-a-very-short-introduction-very-short-introductions.pdf
    • http://www.gorillawalker.com/urban-sustainability-through-environmental-design-approaches-to-time-people-place.pdf
    • http://www.gorillawalker.com/actors-anonymous-a-novel-kindle-edition.pdf
    • http://www.gorillawalker.com/tied-to-the-mast-pirate-gangbang.pdf
    • http://www.gorillawalker.com/mel-bay-albeniz-for-acoustic-guitar.pdf
    • http://www.gorillawalker.com/the-christianization-of-iceland-priests-power-and-social-change-1000.pdf
    • http://www.gorillawalker.com/25-t-ang-poets-index-to-english-translations.pdf
    • http://www.gorillawalker.com/handbook-of-psychoeducational-assessment-a-practical-handbooka-volume-in-the.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/