Malicious PDF — malware analysis report

Static analysis result for SHA-256 64ea994a4b9db708…

MALICIOUS

PDF

34.3 KB Created: 2019-09-08 11:50:52 +03:00 Authoring application: Microsoft Word (via Acrobat PDFWriter 4.0 para Windows) First seen: 2021-06-28
MD5: 4f8bc4b0a05a8335d333423cabe30525 SHA-1: a7bfe950401f970094266ba9bd51d081826c50bb SHA-256: 64ea994a4b9db708a47d5f7f8fde3a0fa3a4a56c72205cd1c2c622bf0b628b64
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier and contains a significant number of embedded external links, a technique often used for SEO manipulation or to host malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external PDF link farm, with the first URL being http://www.gorillawalker.com/yayoi-kusama-inventing-the-singular.pdf. While no scripts were extracted, the sheer volume of links suggests a malicious intent to direct users to potentially harmful resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8018

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/yayoi-kusama-inventing-the-singular.pdf In PDF document text
    • http://www.gorillawalker.com/size-doesn-t-matter-why-small-business-is-big-business.pdfIn PDF document text
    • http://www.gorillawalker.com/the-badminton-magazine-of-sports-and-pastimes-september-1907-containing.pdfIn PDF document text
    • http://www.gorillawalker.com/music-minus-one-bb-trumpet-eb-trumpet-or-d-trumpet.pdfIn PDF document text
    • http://www.gorillawalker.com/faberge-imperial-eggs-and-other-fantasies.pdfIn PDF document text
    • http://www.gorillawalker.com/the-bucolic-plague-1st-first-edition-text-only.pdfIn PDF document text
    • http://www.gorillawalker.com/nobody-s-hero-rescue-me-saga-volume-2.pdfIn PDF document text
    • http://www.gorillawalker.com/the-hunter-s-trail-forever-a-pirate-book-13-kindle.pdfIn PDF document text
    • http://www.gorillawalker.com/derrotero-de-la-costa-del-peru-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/beyond-violence-a-prevention-program-for-criminal-justice-involved-women.pdfIn PDF document text
    • http://www.gorillawalker.com/conquering-math-phobia-a-painless-primer.pdfIn PDF document text
    • http://www.gorillawalker.com/great-wolves-of-passion-alaska-volume-2-convincing-ethan-shane.pdfIn PDF document text
    • http://www.gorillawalker.com/koasati-traditional-narratives-studies-in-the-anthropology-of-north-ame.pdfIn PDF document text
    • http://www.gorillawalker.com/new-history-of-korea.pdfIn PDF document text
    • http://www.gorillawalker.com/making-aston-martin-english-and-german-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/allgemeine-kartensammlung-des-staatsarchivs-konigsberg-spezialinventar-veroffentlichungen-aus-den-archiven.pdfIn PDF document text
    • http://www.gorillawalker.com/every-young-man-god-s-man-workbook-pursuing-confidence-courage.pdfIn PDF document text
    • http://www.gorillawalker.com/in-the-shadow-of-the-state.pdfIn PDF document text
    • http://www.gorillawalker.com/energy-psychology-innovations-in-psychology.pdfIn PDF document text
    • http://www.gorillawalker.com/red-sea-yemen-approaches-to-madiq-kamaran-sudoc-d-5.pdfIn PDF document text
    • http://www.gorillawalker.com/italy-in-the-nineteenth-century-1796-1900-short-oxford-history.pdfIn PDF document text
    • http://www.gorillawalker.com/piano-concerto-no-2-op-16-kalmus-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/secrets-of-successful-speculation.pdfIn PDF document text
    • http://www.gorillawalker.com/a-visit-to-tomb-of-khai-dinh-photo-gallery-kindle.pdfIn PDF document text
    • http://www.gorillawalker.com/my-doodle-diary-art-journal-doodle-books-volume-3.pdfIn PDF document text
    • http://www.gorillawalker.com/research-and-exploration-where-do-they-meet-4th-biennial-sga.pdfIn PDF document text
    • http://www.gorillawalker.com/kingston-upon-hull-trolleybuses.pdfIn PDF document text
    • http://www.gorillawalker.com/psychotherapy-of-schizophrenia-the-treatment-of-choice-unknown-edition-by.pdfIn PDF document text
    • http://www.gorillawalker.com/edelgase-eine-reise-durch-das-periodensystem-essentials-german-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/state-department-counterintelligence-leaks-spies-and-lies.pdfIn PDF document text
    • http://www.gorillawalker.com/mapping-from-aerial-photographs-aspects-of-modern-land-surveying.pdfIn PDF document text
    • http://www.gorillawalker.com/the-hindu-yogi-science-of-breath-a-complete-manual-of.pdfIn PDF document text
    • http://www.gorillawalker.com/two-book-bundle-seeking-paradise-and-swinging-in-paradise.pdfIn PDF document text
    • http://www.gorillawalker.com/coalition-leaders-war-in-iraq.pdfIn PDF document text
    • http://www.gorillawalker.com/ford-sherman-54e100-backhoe-attachment-fordson-major-tractors-opt-pts.pdfIn PDF document text
    • http://www.gorillawalker.com/tadelakt.pdfIn PDF document text
    • http://www.gorillawalker.com/organ-transplant-study-paperback.pdfIn PDF document text
    • http://www.gorillawalker.com/democracy-and-national-identity-in-thailand-rethinking-southeast-asia.pdfIn PDF document text
    • http://www.gorillawalker.com/ghost-hunter-s-guide-to-sheffield.pdfIn PDF document text
    • http://www.gorillawalker.com/engelsauge-nacht-des-todes-german-edition-kindle-edition.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text