Malicious PDF — malware analysis report

Static analysis result for SHA-256 7797daf3ffb8acd4…

MALICIOUS

PDF

34.2 KB Created: 2019-09-18 16:17:17 +03:00 Authoring application: PScript5.dll Version 5.2 (via GPL Ghostscript 8.15) First seen: 2021-06-28
MD5: a3538f7d2925a849d130e4bf74b2a537 SHA-1: 536b972878fdb50ebd0cc24242f354af902aff98 SHA-256: 7797daf3ffb8acd448cfc54dcab7a91e8bc5ddd398a6347098292e5a97dd9c16
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. The ML classifier also flagged the document as malicious. The primary purpose appears to be directing users to a vast collection of documents hosted on 'gorillawalker.com', potentially for SEO manipulation or to serve as a distribution point for further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8529

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/luminescence-techniques-in-solid-state-polymer-research.pdf In PDF document text
    • http://www.gorillawalker.com/real-world-adobe-indesign-cs5.pdfIn PDF document text
    • http://www.gorillawalker.com/50-fashion-designers-you-should-know.pdfIn PDF document text
    • http://www.gorillawalker.com/the-rags-of-north-indian-music-their-structure-and-evolution.pdfIn PDF document text
    • http://www.gorillawalker.com/assessment-and-treatment-activities-for-children-adolescents-and-families-volume.pdfIn PDF document text
    • http://www.gorillawalker.com/chess-conquer-your-friends-with-8-easy-principles-a-cheat.pdfIn PDF document text
    • http://www.gorillawalker.com/clan-novel-ravnos-vampire-the-masquerade.pdfIn PDF document text
    • http://www.gorillawalker.com/bonds-exempt-or-exemptible-from-the-personal-property-tax-under.pdfIn PDF document text
    • http://www.gorillawalker.com/scapegallows.pdfIn PDF document text
    • http://www.gorillawalker.com/pack-mistress-a-novel.pdfIn PDF document text
    • http://www.gorillawalker.com/the-endurance-paradox-bone-health-for-the-endurance-athlete.pdfIn PDF document text
    • http://www.gorillawalker.com/applied-software-measurement-global-analysis-of-productivity-and-quality-kindle.pdfIn PDF document text
    • http://www.gorillawalker.com/worth-keeping-life-with-my-extraordinary-daughter.pdfIn PDF document text
    • http://www.gorillawalker.com/anorthosites-minerals-rocks-and-mountains.pdfIn PDF document text
    • http://www.gorillawalker.com/taste-of-home-halloween-party-favorites-243-eerily-easy-recipes.pdfIn PDF document text
    • http://www.gorillawalker.com/russian-air-power-current-organisation-and-aircraft-of-all-russian.pdfIn PDF document text
    • http://www.gorillawalker.com/s-mtliche-werke-band-8-tageb-cher-viii-reisetageb-cher.pdfIn PDF document text
    • http://www.gorillawalker.com/her-white-lover-bwwm-erotic-romance.pdfIn PDF document text
    • http://www.gorillawalker.com/miriam-in-the-desert.pdfIn PDF document text
    • http://www.gorillawalker.com/corinne-bailey-rae.pdfIn PDF document text
    • http://www.gorillawalker.com/modern-classics-after-leaving-mr-mackenzie-penguin-modern-classics.pdfIn PDF document text
    • http://www.gorillawalker.com/homicide-special-a-year-with-the-lapd-s-elite-detective.pdfIn PDF document text
    • http://www.gorillawalker.com/frantic-left-behind-the-young-trib-force-6-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/paddington-takes-the-air.pdfIn PDF document text
    • http://www.gorillawalker.com/i-m-dangerous-i-m-not-gonna-lie.pdfIn PDF document text
    • http://www.gorillawalker.com/how-to-raise-emotionally-healthy-children-meeting-the-five-critical.pdfIn PDF document text
    • http://www.gorillawalker.com/the-gospel-train.pdfIn PDF document text
    • http://www.gorillawalker.com/dental-materials-pageburst-e-book-on-kno-retail-access-card.pdfIn PDF document text
    • http://www.gorillawalker.com/the-republic-a-socratic-dialogue-complete-student-classics.pdfIn PDF document text
    • http://www.gorillawalker.com/trophy-whitetails-with-pat-and-nicole-reeve-tips-and-tactics.pdfIn PDF document text
    • http://www.gorillawalker.com/kilimanjaro-national-park-1-100-000.pdfIn PDF document text
    • http://www.gorillawalker.com/soviet-chess-1917-1991.pdfIn PDF document text
    • http://www.gorillawalker.com/lab-manual-for-plaster-s-soil-science-and-management-5th.pdfIn PDF document text
    • http://www.gorillawalker.com/essential-elements-2000-bassoon-book-1.pdfIn PDF document text
    • http://www.gorillawalker.com/zan-s-quest-the-chandaran-chronicles.pdfIn PDF document text
    • http://www.gorillawalker.com/handbook-of-asset-and-liability-management-from-models-to-optimal.pdfIn PDF document text
    • http://www.gorillawalker.com/elementary-harmony-theory-and-practice-second-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/the-dead-list.pdfIn PDF document text
    • http://www.gorillawalker.com/cherry-blossoms-for-flute-clarinet-harp-and-string-quartet.pdfIn PDF document text
    • http://www.gorillawalker.com/todd-karr-s-backyard-magic-be-a-magician-use-things.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text