Malicious PDF — malware analysis report

Static analysis result for SHA-256 661e9a1651334f66…

MALICIOUS

PDF

32.0 KB Created: 2020-01-17 19:19:01 +03:00 Authoring application: - (via Acrobat Web Capture 8.0) First seen: 2020-12-28
MD5: 0fffc0423660e1af783b05ff27d0d96f SHA-1: bd07ccd5e2cc6f5571d5d760f5f9091f4e95e3ad SHA-256: 661e9a1651334f66d330a6ec719effe2a10b7a3d596475bf83f8fb4b0e4fa98d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged the document as malicious. The primary purpose appears to be SEO manipulation or directing users to a large number of external resources, rather than delivering a direct payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8447

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/gramatica-lengua-espanola-reglas-y-ejercicios-spanish-edition.pdf In PDF document text
    • http://www.gorillawalker.com/st-gerard-majella-the-mothers-saint.pdfIn PDF document text
    • http://www.gorillawalker.com/advances-in-electrochemical-science-and-engineering-advances-in-electrochemical-sciences.pdfIn PDF document text
    • http://www.gorillawalker.com/taxidermy.pdfIn PDF document text
    • http://www.gorillawalker.com/slab-city-blues-a-song-for-madame-choi-a-science.pdfIn PDF document text
    • http://www.gorillawalker.com/governance-politics-and-policy-in-south-africa.pdfIn PDF document text
    • http://www.gorillawalker.com/lights-camera-hairballs-garfield-at-the-movies.pdfIn PDF document text
    • http://www.gorillawalker.com/lung-cancer-cytopathology-acid-fast-staining-patterns-chinese-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/climate-change-observed-impacts-on-planet-earth.pdfIn PDF document text
    • http://www.gorillawalker.com/moated-sites-of-yorkshire-monograph-series-society-for-medieval-archaeology.pdfIn PDF document text
    • http://www.gorillawalker.com/pigeon-reaktion-books-animal.pdfIn PDF document text
    • http://www.gorillawalker.com/wallpaper-city-guide-genoa-wallpaper-city-guides.pdfIn PDF document text
    • http://www.gorillawalker.com/puerto-apache-fictions-french-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/mandalas-actividad-creadora-creative-activity-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/wild-mating-centaurs-paranormal-mythological-creatures-spanking-book-1-kindle.pdfIn PDF document text
    • http://www.gorillawalker.com/die-feuer-von-erenor-fantasy-fantasy-im-gmeiner-verlag-german.pdfIn PDF document text
    • http://www.gorillawalker.com/a-project-manager-s-guide-to-passing-the-project-management.pdfIn PDF document text
    • http://www.gorillawalker.com/moonshadow-murder-manny-rivera-mysteries.pdfIn PDF document text
    • http://www.gorillawalker.com/the-only-negotiation-book-you-ll-ever-need-find-the.pdfIn PDF document text
    • http://www.gorillawalker.com/banking-law.pdfIn PDF document text
    • http://www.gorillawalker.com/olde-cookbook-1918-sharks-as-food-olde-cookbooks-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/process-industry-procedures-and-training-manual.pdfIn PDF document text
    • http://www.gorillawalker.com/i-m-an-atheist-and-you-should-be-one-too.pdfIn PDF document text
    • http://www.gorillawalker.com/i-did-not-even-exist-textual-culture-and-alternate-history.pdfIn PDF document text
    • http://www.gorillawalker.com/all-our-empty-places-a-time-of-grace-book-2.pdfIn PDF document text
    • http://www.gorillawalker.com/emanuel-law-outlines-torts.pdfIn PDF document text
    • http://www.gorillawalker.com/promethean-pandoras-book.pdfIn PDF document text
    • http://www.gorillawalker.com/agricultural-and-livestock-activities-in-latin-america-a-partial-bibliography.pdfIn PDF document text
    • http://www.gorillawalker.com/21-anos-de-la-vuelta-a-costa-rica-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/why-can-t-my-child-behave-why-can-t-she.pdfIn PDF document text
    • http://www.gorillawalker.com/icd-9-cm-2007-vols-1-2-3-hospital-payer.pdfIn PDF document text
    • http://www.gorillawalker.com/outdoor-banner-vacation-bible-school-2015-bible-blast-to-the.pdfIn PDF document text
    • http://www.gorillawalker.com/the-all-time-biggest-sports-jerks-and-other-goofballs-cads.pdfIn PDF document text
    • http://www.gorillawalker.com/local-space-2200-ad.pdfIn PDF document text
    • http://www.gorillawalker.com/analysis-of-incomplete-multivariate-data-chapman-hall-crc-monographs-on.pdfIn PDF document text
    • http://www.gorillawalker.com/the-life-of-pope-leo-xiii-including-a-graphic-description.pdfIn PDF document text
    • http://www.gorillawalker.com/who-wants-candy.pdfIn PDF document text
    • http://www.gorillawalker.com/el-caracter-neurotico-the-neurotic-character-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/myofascial-manipulation-theory-and-clinical-application-3rd-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/the-apocalyptic-imagination-an-introduction-to-the-jewish-matrix-of.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text