Malicious PDF — malware analysis report

Static analysis result for SHA-256 66b25bfdc3a3340e…

MALICIOUS

PDF

41.1 KB Created: 2018-11-14 11:20:03 +03:00 Authoring application: Acrobat PDFMaker 6.0 for Word (via Acrobat Distiller 6.0 (Windows))
MD5: 28effa45e00c2d3c033984c0ca4ba445 SHA-1: 804b2d3bd832d4b16438393af22133f2dc73a56b SHA-256: 66b25bfdc3a3340ecb8c2003860d80c694e26f25678d72914be6b1610ab65404
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files on the domain 'gorillawalker.com'. This is indicative of a link farm or SEO manipulation tactic. While no explicit script was found, the ML classifier and the heuristic firing strongly suggest malicious intent, likely to distribute further content or manipulate search engine rankings. The presence of embedded URLs and the ML classification contribute to the confidence in this assessment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9181

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/bloom-s-major-dramatists-set-26-volumes.pdf
    • http://www.gorillawalker.com/memos-from-midlife-24-parables-of-adult-adjustment.pdf
    • http://www.gorillawalker.com/plowed-and-planted-by-the-ladyboy-kindle-edition.pdf
    • http://www.gorillawalker.com/chloe-s-double-draw-king-s-bluff-wyoming-siren-publishing.pdf
    • http://www.gorillawalker.com/from-italy-with-love-kindle-edition.pdf
    • http://www.gorillawalker.com/a-first-course-in-probability-9th-edition.pdf
    • http://www.gorillawalker.com/november-hesperus-classics.pdf
    • http://www.gorillawalker.com/the-british-at-passchendaele-1916-18-images-of-war.pdf
    • http://www.gorillawalker.com/race-and-the-incidence-of-environmental-hazards-a-time-for.pdf
    • http://www.gorillawalker.com/techniques-of-thin-layer-chromatography-in-amino-acid-and-peptide.pdf
    • http://www.gorillawalker.com/new-guinea-the-last-unknown.pdf
    • http://www.gorillawalker.com/psalms-volume-1-encountering-god-new-community-bible-study-series.pdf
    • http://www.gorillawalker.com/the-genesis-of-kant-s-critique-of-judgment.pdf
    • http://www.gorillawalker.com/unruly-corporatism-associational-life-in-twentieth-century-egypt.pdf
    • http://www.gorillawalker.com/design-for-living-alfred-lunt-and-lynn-fontanne.pdf
    • http://www.gorillawalker.com/binibonhonpo-aimi-shashinshu-vol1-binibonhonpo-shashinshu-japanese-edition-kindle-edition.pdf
    • http://www.gorillawalker.com/i-am-a-roamer-bold-tb-piano-sheet-music.pdf
    • http://www.gorillawalker.com/tokaido-texts-and-tales-tokaido-gojusan-tsui-by-kuniyoshi-hiroshige.pdf
    • http://www.gorillawalker.com/amelia-earhart-rookie-biographies.pdf
    • http://www.gorillawalker.com/mel-bay-new-dimensions-in-classical-guitar-for-children.pdf
    • http://www.gorillawalker.com/poet-russian-edition.pdf
    • http://www.gorillawalker.com/it-s-not-about-the-hunter-easy-to-read-wonder.pdf
    • http://www.gorillawalker.com/miles-to-go-the-lost-years.pdf
    • http://www.gorillawalker.com/anxiety-disorders-in-children-and-adolescents-cambridge-child-and-adolescent.pdf
    • http://www.gorillawalker.com/quantum-memory-working-magic-with-your-memory.pdf
    • http://www.gorillawalker.com/usar-el-cerebro-conocer-nuestra-mente-para-vivir-mejor-spanish.pdf
    • http://www.gorillawalker.com/australia-west.pdf
    • http://www.gorillawalker.com/multiple-regression-and-beyond.pdf
    • http://www.gorillawalker.com/the-martins-dream-big.pdf
    • http://www.gorillawalker.com/joseph-and-aseneth-guides-to-the-apocrypha-and-pseudepigrap.pdf
    • http://www.gorillawalker.com/ellas-mismas-spanish-edition.pdf
    • http://www.gorillawalker.com/palace-council.pdf
    • http://www.gorillawalker.com/hannah-s-ghost-kindle-edition.pdf
    • http://www.gorillawalker.com/restoration-and-reaction-1815-1848-the-cambridge-history-of-modern.pdf
    • http://www.gorillawalker.com/war-crimes-investigation-kindle-edition.pdf
    • http://www.gorillawalker.com/negotiation-and-design-for-the-self-organizing-city-gaming-as.pdf
    • http://www.gorillawalker.com/tlahtolnahuatilli-curso-elemental-de-nahuatl-clasico-en-15-fasciculos-v.pdf
    • http://www.gorillawalker.com/jane-goodall-chimpanzee-expert-activist-history-maker-biographies-abdo.pdf
    • http://www.gorillawalker.com/basics-fashion-design-01-research-and-design-second-edition.pdf
    • http://www.gorillawalker.com/how-to-teach-your-children-about-sex-without-making-a.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/