Malicious PDF — malware analysis report

Static analysis result for SHA-256 755597a8b4c9d80d…

MALICIOUS

PDF

33.3 KB Created: 2020-02-13 12:46:30 +03:00 Authoring application: PScript5.dll Version 5.2.2 (via Acrobat Distiller 7.0.5 (Windows)) First seen: 2021-06-28
MD5: 021aedb9b2ea7d56743f0ba98e49d2ed SHA-1: 81ddb08e8e9ebb2ce9334a41966fbaa1720ec2f7 SHA-256: 755597a8b4c9d80d2ebfadab998b579484373454e40b87b7a025f721d3bfafbd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier and contains a large number of embedded links to external PDF files hosted on 'gorillawalker.com'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine a more specific attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8529

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/later-travels-the-i-tatti-renaissance-library.pdf In PDF document text
    • http://www.gorillawalker.com/encyclopedia-of-an-ordinary-life-1.pdfIn PDF document text
    • http://www.gorillawalker.com/travels-in-siberia-including-excursions-northwards-down-the-obi-to.pdfIn PDF document text
    • http://www.gorillawalker.com/the-coldest-war-milkweed.pdfIn PDF document text
    • http://www.gorillawalker.com/biostatistics-a-computing-approach-chapman-hall-crc-biostatistics-series.pdfIn PDF document text
    • http://www.gorillawalker.com/how-to-identify-plants.pdfIn PDF document text
    • http://www.gorillawalker.com/constructing-lebanon-a-century-of-literary-narratives.pdfIn PDF document text
    • http://www.gorillawalker.com/numerical-methods-for-ordinary-differential-equations-initial-value-problems-springer.pdfIn PDF document text
    • http://www.gorillawalker.com/the-modern-housewife-or-m-nag-re-comprising-nearly-one.pdfIn PDF document text
    • http://www.gorillawalker.com/the-control-of-fuddle-and-flash-a-sociological-history-of.pdfIn PDF document text
    • http://www.gorillawalker.com/coaching-cheerleading-successfully-coaching-successfully-series-paperback.pdfIn PDF document text
    • http://www.gorillawalker.com/facts-on-the-mind-sciences-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/south-african-special-forces-elite-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/one-word-that-will-change-your-life-expanded-edition-kindle.pdfIn PDF document text
    • http://www.gorillawalker.com/geology-of-the-fort-hall-area-degree-sheet-44-s.pdfIn PDF document text
    • http://www.gorillawalker.com/clinical-application-of-mechanical-ventilation-2e.pdfIn PDF document text
    • http://www.gorillawalker.com/those-crazy-caiques.pdfIn PDF document text
    • http://www.gorillawalker.com/bird-island.pdfIn PDF document text
    • http://www.gorillawalker.com/adobe-acrobat-xi-classroom-in-a-book.pdfIn PDF document text
    • http://www.gorillawalker.com/bataan-diary-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/krazy-ignatz-1941-1942-a-ragout-of-raspberries-krazy-kat.pdfIn PDF document text
    • http://www.gorillawalker.com/incubus-master-captured-7-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/the-geology-of-chatsworth-house.pdfIn PDF document text
    • http://www.gorillawalker.com/the-category-of-the-person-anthropology-philosophy-history.pdfIn PDF document text
    • http://www.gorillawalker.com/partners-in-life-and-love-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/collected-works-of-harry-g-johnson-the-economics-of-exchange.pdfIn PDF document text
    • http://www.gorillawalker.com/the-case-of-the-gilded-lily-perry-mason-mystery.pdfIn PDF document text
    • http://www.gorillawalker.com/under-arrest.pdfIn PDF document text
    • http://www.gorillawalker.com/handbook-of-smart-coatings-for-materials-protection-woodhead-publishing-series.pdfIn PDF document text
    • http://www.gorillawalker.com/expositions-of-holy-scripture-the-book-of-esther-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/michelangelo-his-epic-life.pdfIn PDF document text
    • http://www.gorillawalker.com/naturalistic-photography-with-an-introd-by-peter-pollack.pdfIn PDF document text
    • http://www.gorillawalker.com/unwanted-affection-unwanted-series-book-2-volume-2.pdfIn PDF document text
    • http://www.gorillawalker.com/speech-of-o-h-browning-of-illinois-on-the-confiscation.pdfIn PDF document text
    • http://www.gorillawalker.com/the-milan-castle-how-and-when-it-arose-it-was.pdfIn PDF document text
    • http://www.gorillawalker.com/sid-s-way-the-life-and-death-of-sid-vicious.pdfIn PDF document text
    • http://www.gorillawalker.com/historia-de-la-acumulaci.pdfIn PDF document text
    • http://www.gorillawalker.com/language-difficulties-in-an-educational-context.pdfIn PDF document text
    • http://www.gorillawalker.com/destined-a-novel-of-the-tarot.pdfIn PDF document text
    • http://www.gorillawalker.com/53-melodious-etudes-book-1-saxophone.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text