Malicious PDF — malware analysis report

Static analysis result for SHA-256 62eba3ba397bc0cf…

MALICIOUS

PDF

36.3 KB Created: 2019-05-24 00:42:10 +03:00 Authoring application: FrameMaker 7.0 (via Acrobat Distiller 5.0.5 (Windows); modified using iText® 5.5.4 ©2000-2014 iText Group NV (AGPL-version)) First seen: 2021-06-28
MD5: fc9c009326e4cf26fab8c0f35dd7aaab SHA-1: 87a4912380e9662645632d0deb957f68c596b50f SHA-256: 62eba3ba397bc0cfb4bffccc1b71369a30861c4a95ec7f2d367f04048c6c7f9a
132 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to other PDF files, indicative of a link farm designed for SEO manipulation. The 'SE_PASSWORD_ARCHIVE_LURE' heuristic suggests a potential attempt to bypass security controls by encrypting payloads, although no actual payload was directly observed in this sample. The ML classifier also flagged the document as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7977

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/faruqi-s-law-dictionary-english-meanings-and-definitions-of-words.pdf In PDF document text
    • http://www.gorillawalker.com/the-unfinished-nation-a-concise-history-of-the-american-people.pdfIn PDF document text
    • http://www.gorillawalker.com/chocolate-fads-folklore-fantasies-1-000-chunks-of-chocolate-information.pdfIn PDF document text
    • http://www.gorillawalker.com/rivers-of-memory-the-pruett-series.pdfIn PDF document text
    • http://www.gorillawalker.com/the-latter-days-the-best-of-led-zeppelin-vol-2.pdfIn PDF document text
    • http://www.gorillawalker.com/english-grammar-and-composition-a-complete-handbook.pdfIn PDF document text
    • http://www.gorillawalker.com/self-efficacy-thought-control-of-action.pdfIn PDF document text
    • http://www.gorillawalker.com/el-sexto-hombre-b-de-books-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/gender-and-law-introduction-to-paperback.pdfIn PDF document text
    • http://www.gorillawalker.com/constitutional-law-and-politics-civil-rights-and-civil-liberties.pdfIn PDF document text
    • http://www.gorillawalker.com/the-farmer-colonial-people.pdfIn PDF document text
    • http://www.gorillawalker.com/forever-vampire.pdfIn PDF document text
    • http://www.gorillawalker.com/forbidden-desire-2.pdfIn PDF document text
    • http://www.gorillawalker.com/plague-riders-after-the-dust-settled.pdfIn PDF document text
    • http://www.gorillawalker.com/iluminaciones-y-an-cdotas-plataforma-narrativa-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/d-hancarville-the-complete-collection-of-antiquities-from-the-cabinet.pdfIn PDF document text
    • http://www.gorillawalker.com/on-y-va-level-1.pdfIn PDF document text
    • http://www.gorillawalker.com/success-secrets-of-the-online-marketing-superstars-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/de-la-geometrie-algebrique-aux-formes-automorphes-une-collection-d.pdfIn PDF document text
    • http://www.gorillawalker.com/aristophanes-lysistrata-comedies-of-aristophanes-ancient-greek-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/el-universo-de-los-aztecas-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/history-of-egypt-chaldea-syria-babylonia-and-assyria-v6-1903.pdfIn PDF document text
    • http://www.gorillawalker.com/bob-marley-songs-of-freedom.pdfIn PDF document text
    • http://www.gorillawalker.com/the-creative-society-how-the-future-can-be-won.pdfIn PDF document text
    • http://www.gorillawalker.com/kafka-toward-a-minor-literature-theory-and-history-of-literature.pdfIn PDF document text
    • http://www.gorillawalker.com/group-dynamics-for-high-risk-teams-a-team-resource-management.pdfIn PDF document text
    • http://www.gorillawalker.com/the-fall-of-heartless-horse-little-house-on-the-bowery.pdfIn PDF document text
    • http://www.gorillawalker.com/the-story-of-the-chosen-people-yesterday-s-classics.pdfIn PDF document text
    • http://www.gorillawalker.com/brevisima-relacion-de-la-destruccion-de-las-indias.pdfIn PDF document text
    • http://www.gorillawalker.com/are-you-really-a-genius-timeless-tests-for-the-irritatingly.pdfIn PDF document text
    • http://www.gorillawalker.com/jesus-on-trial-stageplay.pdfIn PDF document text
    • http://www.gorillawalker.com/handbook-of-estate-improvement-external-areas-v-2.pdfIn PDF document text
    • http://www.gorillawalker.com/the-everything-green-smoothies-book-includes-the-green-go-getter.pdfIn PDF document text
    • http://www.gorillawalker.com/the-carter-boys-books-1-4-complete-series.pdfIn PDF document text
    • http://www.gorillawalker.com/culture-shock-saudi-arabia-a-survival-guide-to-customs-and.pdfIn PDF document text
    • http://www.gorillawalker.com/the-monastic-diurnal-or-day-hours-of-the-monastic-breviary.pdfIn PDF document text
    • http://www.gorillawalker.com/tommy-igoe-groove-essentials-1-0-2-0-complete-includes.pdfIn PDF document text
    • http://www.gorillawalker.com/progenitor-s-curse-vera-s-revenge-book-one.pdfIn PDF document text
    • http://www.gorillawalker.com/wheelchair-travel-to-japan-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/who-likes-the-rain-exploring-the-elements.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text