Malicious PDF — malware analysis report

Static analysis result for SHA-256 82d55fbaf3abaa63…

MALICIOUS

PDF

38.7 KB Created: 2018-11-23 20:29:57 +03:00 Authoring application: Adobe PageMaker 6.52 (via Acrobat Distiller 3.01 for Windows)
MD5: 9a9663534d8b09c68c7b6b504a0e7659 SHA-1: 4a08cd2616caee653aa16ea174e1bc7c7a812a7c SHA-256: 82d55fbaf3abaa6371cb1910b0b62f4796e1ab159db60a0acd68f139bcdf6f81
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was detected as malicious by ClamAV and an ML classifier, and exhibits a critical heuristic for a large number of embedded external links. These links, primarily pointing to PDF files on 'gorillawalker.com', suggest a link farm or redirection mechanism. The embedded URLs are likely used to lure users to malicious sites or download further malware, aligning with a spearphishing attachment attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8702

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7277865-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7277865-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/frankenstein-or-the-modern-prometheus-enriched-classics-kindle-edition.pdf
    • http://www.gorillawalker.com/souvenirs-of-travel.pdf
    • http://www.gorillawalker.com/take-a-dam-tour-a-kid-s-guide-to-hoover.pdf
    • http://www.gorillawalker.com/delirious-new-york-a-retroactive-manifesto-for-manhattan.pdf
    • http://www.gorillawalker.com/indian-silver-jewelry-of-the-southwest.pdf
    • http://www.gorillawalker.com/experiments-with-light-true-books-science-experiments.pdf
    • http://www.gorillawalker.com/vulture-s-kiss-the-ibis-prophecy-book-two.pdf
    • http://www.gorillawalker.com/moldova-kindle-edition.pdf
    • http://www.gorillawalker.com/driving-test-success-premium-pc-2014-15.pdf
    • http://www.gorillawalker.com/53-interesting-ways-to-communicate-your-research-professional-and-higher.pdf
    • http://www.gorillawalker.com/solar-water-heating-reference-manual-ee02.pdf
    • http://www.gorillawalker.com/the-advancement-of-learning.pdf
    • http://www.gorillawalker.com/ecologically-based-pest-management-new-solutions-for-a-new-century.pdf
    • http://www.gorillawalker.com/genome-analysis-and-bioinformatics-a-practical-approach.pdf
    • http://www.gorillawalker.com/my-first-story-scottish-tales.pdf
    • http://www.gorillawalker.com/1001-whiskies-you-must-taste-before-you-die.pdf
    • http://www.gorillawalker.com/large-print-junior-word-search-puzzles-volume-1.pdf
    • http://www.gorillawalker.com/lloyd-s-law-reports-1919-91-v-6-consolidated-index.pdf
    • http://www.gorillawalker.com/civil-military-conflict-in-imperial-russia-1881-1914-princeton-legacy.pdf
    • http://www.gorillawalker.com/wasatch-wildflowers.pdf
    • http://www.gorillawalker.com/developing-managing-your-school-guidance-counseling-programs.pdf
    • http://www.gorillawalker.com/aenied-of-virgil.pdf
    • http://www.gorillawalker.com/one-tank-trips-great-getaways-in-around-ohio-and-tales.pdf
    • http://www.gorillawalker.com/strengthening-statehood-capabilities-for-successful-transitions-in-the-middle-east.pdf
    • http://www.gorillawalker.com/the-malay-archipelago-the-land-of-the-orang-utan-and.pdf
    • http://www.gorillawalker.com/nag-hammadi-codices-introduction-1984.pdf
    • http://www.gorillawalker.com/my-first-animals.pdf
    • http://www.gorillawalker.com/oxford-book-of-aphorisms.pdf
    • http://www.gorillawalker.com/heart-of-nightfang-spire-dungeons-dragons-d20-3-0-fantasy.pdf
    • http://www.gorillawalker.com/skinny-dip.pdf
    • http://www.gorillawalker.com/technitunes-viola.pdf
    • http://www.gorillawalker.com/chris-brown-hip-hop-biographies.pdf
    • http://www.gorillawalker.com/reducing-the-m-a-risks-the-role-of-it-in.pdf
    • http://www.gorillawalker.com/song-of-the-raven.pdf
    • http://www.gorillawalker.com/du-lait-au-fiel-lire-et-s-entrainer-french-edition.pdf
    • http://www.gorillawalker.com/uninformed-why-people-seem-to-know-so-little-about-politics.pdf
    • http://www.gorillawalker.com/baptists-free-and-faithful-christian-discipleship-in-the-21st-century.pdf
    • http://www.gorillawalker.com/altered-reality-the-exilon-5-trilogy-book-2.pdf
    • http://www.gorillawalker.com/dk-eyewitness-travel-guide-scotland.pdf
    • http://www.gorillawalker.com/dazzle-volume-1.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/