Malicious PDF — malware analysis report

Static analysis result for SHA-256 62e29646cbda170b…

MALICIOUS

PDF

32.9 KB Created: 2019-07-01 18:05:49 +03:00 Authoring application: SYSTEM400 Rev 16.02 (via Acrobat Distiller 4.05 for Windows, Powered by PDF Polisher Pro 5.01 420) First seen: 2021-06-28
MD5: 2cce671f225a0fc0bf47c051404a73bf SHA-1: 17e8ea7f0bc7b99837357ef37ed36529e04d7ed2 SHA-256: 62e29646cbda170bf67861d5d0eb14cd47dd4c5766886b540756758219017aaa
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF documents hosted on the same domain, suggesting a link farm or SEO manipulation tactic. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine a more specific intent beyond link distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8529

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/almond-cookbook-the-healing-almond-book-31-superfood-almond-recipes.pdf In PDF document text
    • http://www.gorillawalker.com/practical-risk-adjusted-performance-measurement.pdfIn PDF document text
    • http://www.gorillawalker.com/the-celestine-priory-at-leuven-from-monastery-to-library-varia.pdfIn PDF document text
    • http://www.gorillawalker.com/making-money.pdfIn PDF document text
    • http://www.gorillawalker.com/david-busch-s-canon-eos-rebel-t4i-650d-guide-to.pdfIn PDF document text
    • http://www.gorillawalker.com/good-mornings-great-breakfasts-and-brunches-for-starting-the-day.pdfIn PDF document text
    • http://www.gorillawalker.com/the-slaughterman.pdfIn PDF document text
    • http://www.gorillawalker.com/historical-archeology-of-tourism-in-yellowstone-national-park-when-the.pdfIn PDF document text
    • http://www.gorillawalker.com/men-who-made-a-new-physics-physicists-and-the-quantum.pdfIn PDF document text
    • http://www.gorillawalker.com/who-was-martin-luther-king-jr-who-was-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/the-designer-s-eye.pdfIn PDF document text
    • http://www.gorillawalker.com/project-rainbow-how-british-cycling-reached-the-top-of-the.pdfIn PDF document text
    • http://www.gorillawalker.com/french-lonely-planet-phrasebook.pdfIn PDF document text
    • http://www.gorillawalker.com/bed-methuen-modern-plays.pdfIn PDF document text
    • http://www.gorillawalker.com/the-pharmaceutical-industry-and-dependency-in-the-third-world.pdfIn PDF document text
    • http://www.gorillawalker.com/the-modern-benoni-revealed-batsford-chess-books.pdfIn PDF document text
    • http://www.gorillawalker.com/why-would-a-child-lie.pdfIn PDF document text
    • http://www.gorillawalker.com/hacking-wireless-networks-the-ultimate-hands-on-guide.pdfIn PDF document text
    • http://www.gorillawalker.com/electronics-lab-manual.pdfIn PDF document text
    • http://www.gorillawalker.com/la-energ-a-de-las-letras-hebreas-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/western-himalaya-and-tibet-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/we-will-end-the-conflict-now-victory-over-pornography-from.pdfIn PDF document text
    • http://www.gorillawalker.com/maximum-joy-1-john-relationship-or-fellowship.pdfIn PDF document text
    • http://www.gorillawalker.com/a-handbook-of-traditional-chinese-gynecology.pdfIn PDF document text
    • http://www.gorillawalker.com/typee-peep-at-polynesian-life.pdfIn PDF document text
    • http://www.gorillawalker.com/seed-by-seed-the-legend-and-legacy-of-john-appleseed.pdfIn PDF document text
    • http://www.gorillawalker.com/hbr-s-10-must-reads-on-strategy-including-featured-article.pdfIn PDF document text
    • http://www.gorillawalker.com/all-about-market-timing.pdfIn PDF document text
    • http://www.gorillawalker.com/handbuch-policy-forschung-german-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/love-death-my-journey-through-the-valley-of-the-shadow.pdfIn PDF document text
    • http://www.gorillawalker.com/the-virgin-of-flames.pdfIn PDF document text
    • http://www.gorillawalker.com/us-army-technical-manual-operator-organizational-direct-support-and-general.pdfIn PDF document text
    • http://www.gorillawalker.com/essentials-of-corrections.pdfIn PDF document text
    • http://www.gorillawalker.com/heroes-of-the-blues-boxed-trading-card-set-by-r.pdfIn PDF document text
    • http://www.gorillawalker.com/kinematics-dynamics-and-design-of-machinery-comes-with-cd.pdfIn PDF document text
    • http://www.gorillawalker.com/illustrator-cs6-visual-quickstart-guide-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/defending-the-three-point-shot-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/the-human-eye-structure-and-function.pdfIn PDF document text
    • http://www.gorillawalker.com/mr-selden-s-map-of-china-decoding-the-secrets-of.pdfIn PDF document text
    • http://www.gorillawalker.com/capstone-exemplary-lessons-for-high-school-economics-teacher-s-guide.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text