Malicious PDF — malware analysis report

Static analysis result for SHA-256 7e3f6c8c3dee9c04…

MALICIOUS

PDF

42.6 KB Created: 2018-12-15 20:54:14 +03:00 Authoring application: -
MD5: 1fa1ecd3fbe4fa63c21afff5df997e15 SHA-1: a6dfd4654373485c496a1ccf604a3685c8ce9f8c SHA-256: 7e3f6c8c3dee9c047bd4befc5ec94cb56c523a873f160f432ce9bc8aa9feeef6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents on the domain www.gorillawalker.com. This behavior is indicative of a link farm or a SEO poisoning attempt, where the PDF itself serves as a lure to drive traffic to a specific website. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine a more specific attack pattern or intent beyond link redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8872

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/10-seconds-per-question-toeic-test-english-grammar-2011-isbn.pdf
    • http://www.gorillawalker.com/the-eric-dolphy-collection-artist-transcriptions-woodwinds.pdf
    • http://www.gorillawalker.com/rebecca-s-garden-four-seasons-to-grow-on.pdf
    • http://www.gorillawalker.com/mcgraw-hill-s-taxation-of-business-entities-2016-edition.pdf
    • http://www.gorillawalker.com/churchill-kindle-edition.pdf
    • http://www.gorillawalker.com/how-to-hug-a-porcupine-kindle-edition.pdf
    • http://www.gorillawalker.com/a-gathering-of-spies-kindle-edition.pdf
    • http://www.gorillawalker.com/illustrated-the-history-of-man-in-space.pdf
    • http://www.gorillawalker.com/beverly-clark-s-book-of-wedding-cakes-beverly-clark-minis.pdf
    • http://www.gorillawalker.com/recorder-sonata-in-b-minor-recorder-part.pdf
    • http://www.gorillawalker.com/a-place-called-milagro-de-la-paz.pdf
    • http://www.gorillawalker.com/the-beer-stein-book-illustrated-catalog-current-prices-collector-s.pdf
    • http://www.gorillawalker.com/confesiones-prohibidas-xxx-9-spanish-edition.pdf
    • http://www.gorillawalker.com/careers-in-health-information-technology.pdf
    • http://www.gorillawalker.com/15-documents-and-speeches-that-built-america-unique-classics-declaration.pdf
    • http://www.gorillawalker.com/how-to-survive-and-thrive-on-food-stamps-how-to.pdf
    • http://www.gorillawalker.com/the-collected-critical-heritage-i-thomas-carlyle-the-critical-heritage.pdf
    • http://www.gorillawalker.com/kane-cornes.pdf
    • http://www.gorillawalker.com/the-cowboy-rock-star-somewhere-texas-book-1-volume-1.pdf
    • http://www.gorillawalker.com/complete-maya-programming-an-extensive-guide-to-mel-and-c.pdf
    • http://www.gorillawalker.com/betty-wales-sophomore.pdf
    • http://www.gorillawalker.com/florence-map-city-plan-i-city-map-german-edition.pdf
    • http://www.gorillawalker.com/full-exam-guides-adhd-diagnosis-in-preschoolers-mental-health-an.pdf
    • http://www.gorillawalker.com/the-fascinating-world-of-graph-theory-kindle-edition.pdf
    • http://www.gorillawalker.com/in-the-midst-of-a-storm-a-pride-and-prejudice.pdf
    • http://www.gorillawalker.com/how-to-talk-so-men-will-listen.pdf
    • http://www.gorillawalker.com/industrial-wastewater-source-control-an-inspection-guide.pdf
    • http://www.gorillawalker.com/lippincott-s-online-course-for-abrams-clinical-drug-therapy-abrams.pdf
    • http://www.gorillawalker.com/journal-of-colonel-george-washington-commanding-a-detachment-of-virginia.pdf
    • http://www.gorillawalker.com/the-dumb-white-husband-s-guide-to-babies.pdf
    • http://www.gorillawalker.com/mind-maps-for-business-2nd-edn-using-the-ultimate-thinking.pdf
    • http://www.gorillawalker.com/rsmeans-square-foot-costs-2011.pdf
    • http://www.gorillawalker.com/the-heirloom-house-how-ebay-and-i-decorated-and-furnished.pdf
    • http://www.gorillawalker.com/archana-book.pdf
    • http://www.gorillawalker.com/blackjack-tome-2.pdf
    • http://www.gorillawalker.com/the-law-of-real-property.pdf
    • http://www.gorillawalker.com/healing-herbs-from-your-kitchen-a-willowbark-tea-book.pdf
    • http://www.gorillawalker.com/mercy-sparx-0-1-comic-book-bundle-kindle-edition.pdf
    • http://www.gorillawalker.com/how-to-scout-football.pdf
    • http://www.gorillawalker.com/strange-new-worlds-star-trek.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/