Malicious PDF — malware analysis report

Static analysis result for SHA-256 59e434656c5d12e9…

MALICIOUS

PDF

43.5 KB Created: 2018-11-30 20:24:48 +03:00 Authoring application: pdfTeX-1.40.14 (via Revision 5)
MD5: bcad6547fecb0b83d42c51c4181110f0 SHA-1: 2af43b47d0e0766507adf653ec6ea4782da14eb7 SHA-256: 59e434656c5d12e9e2f9f56a63c3ed4df0c253e3dcd6f047cb20cbae25a2bf0b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged the PDF as malicious with high confidence. While no scripts were extracted, the sheer volume of links suggests a malicious intent, possibly to distribute malware or engage in phishing, by leveraging SEO techniques to disguise the malicious nature of the links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9171

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/international-law-reports-volume-105.pdf
    • http://www.gorillawalker.com/pond-life-nature-activity-book-nature-activity-book-series.pdf
    • http://www.gorillawalker.com/virtual-patient-encounters-for-emt-prehospital-care-revised-reprint-4e.pdf
    • http://www.gorillawalker.com/the-woman-inside.pdf
    • http://www.gorillawalker.com/the-shy-poet-re-emerges-more-poetry-from-the-soul.pdf
    • http://www.gorillawalker.com/nueva-relacion-que-contiene-los-viages-de-tomas-gage-en.pdf
    • http://www.gorillawalker.com/an-anthropological-defense-of-god.pdf
    • http://www.gorillawalker.com/mcdougal-school-handwriting-22-1-student-edition-con-1987.pdf
    • http://www.gorillawalker.com/the-ketogenic-diet-a-treatment-for-children-and-others-with.pdf
    • http://www.gorillawalker.com/steel.pdf
    • http://www.gorillawalker.com/study-and-master-accounting-grade-11-teacher-s-guide-afrikaans.pdf
    • http://www.gorillawalker.com/countdown-to-christmas-devotions-for-families.pdf
    • http://www.gorillawalker.com/the-rough-guide-to-congo-gold-music-rough-guides.pdf
    • http://www.gorillawalker.com/robin-ward-s-vancouver.pdf
    • http://www.gorillawalker.com/reinforced-concrete-fundamentals.pdf
    • http://www.gorillawalker.com/skill-based-practice-for-fourth-grade-math-games.pdf
    • http://www.gorillawalker.com/matthew-ironside-expository-commentaries.pdf
    • http://www.gorillawalker.com/husserl-s-transcendental-phenomenology-nature-spirit-and-life.pdf
    • http://www.gorillawalker.com/n-j-agents-propose-auto-crisis-plan-an-article-from.pdf
    • http://www.gorillawalker.com/the-torts-process-8th-edition-aspen-casebook.pdf
    • http://www.gorillawalker.com/dune-boy-the-early-years-of-a-naturalist.pdf
    • http://www.gorillawalker.com/the-magic-of-zambia-2001-handbook.pdf
    • http://www.gorillawalker.com/persepolis-persepolis-complete-edition-french-edition.pdf
    • http://www.gorillawalker.com/mechanical-reliability-improvement-probability-and-statistics-for-experimental-testing-mechanical.pdf
    • http://www.gorillawalker.com/brooklyn-line-terminus-cosmos-valerian-vol-10.pdf
    • http://www.gorillawalker.com/analysing-the-french-revolution-3ed-interactive-textbook.pdf
    • http://www.gorillawalker.com/devil-s-playground-kris-chase-book-2.pdf
    • http://www.gorillawalker.com/lactic-acid-bacteria-genetics-metabolism-and-applications-proceedings-of-the.pdf
    • http://www.gorillawalker.com/little-boy-the-arts-of-japan-146-s-exploding-subculture.pdf
    • http://www.gorillawalker.com/buongiorno-italia-grammar-workbk.pdf
    • http://www.gorillawalker.com/south-beach-diet-desserts-delicious-desserts-that-promote-weight-loss.pdf
    • http://www.gorillawalker.com/auctioneer-exam-flashcard-study-system-auctioneer-test-practice-questions-review.pdf
    • http://www.gorillawalker.com/x-ray-optics-high-energy-resolution-applications-springer-series-in.pdf
    • http://www.gorillawalker.com/philosophy-made-simple.pdf
    • http://www.gorillawalker.com/handwriting-manuscript-uppercase-letters-colour-dots-the-alphabet-learning-method.pdf
    • http://www.gorillawalker.com/lpic-1-linux-professional-institute-certification-study-guide-exams-101.pdf
    • http://www.gorillawalker.com/killer-blog-folge-2-der-erste-auftrag-german-edition.pdf
    • http://www.gorillawalker.com/jewish-holidays-books-for-kids-children-s-books-with-good.pdf
    • http://www.gorillawalker.com/bond-investing-for-dummies-2nd-edition-by-wild-russell-2nd.pdf
    • http://www.gorillawalker.com/dragonheart.pdf
    • http://www.gorillawalker.com/nueva-r
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/