Malicious PDF — malware analysis report

Static analysis result for SHA-256 85d84b1f7111bbdd…

MALICIOUS

PDF

43.5 KB Created: 2018-11-15 18:34:09 +03:00 Authoring application: www.freepdfconvert.com (via http://www.freepdfconvert.com) First seen: 2019-01-11
MD5: 5abe12eda1e22d67cd5470477d3fea82 SHA-1: 0c77c186950d4294bbb8bdf8b073d274ae2048b0 SHA-256: 85d84b1f7111bbddfbb485f0ea7d63ec1daf81a36ea8bfaf5af433f8bf0fa6df
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. The ML classifier also flagged the document as malicious. The primary purpose appears to be directing users to a website hosting numerous PDF documents, potentially for SEO spam or to distribute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9171

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/american-buses-city-school-yard-and-highway-crestline-series.pdf In PDF document text
    • http://www.gorillawalker.com/it-s-a-breeze-gullah-gullah-island.pdfIn PDF document text
    • http://www.gorillawalker.com/business-and-tax-guide-for-antiques-collectibles.pdfIn PDF document text
    • http://www.gorillawalker.com/pediatric-tricky-topics-volume-1-a-practically-painless-review.pdfIn PDF document text
    • http://www.gorillawalker.com/arthritis-the-johns-hopkins-white-papers.pdfIn PDF document text
    • http://www.gorillawalker.com/the-day-the-crayons-quit-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/westinghouse-j40-axial-turbojet-family-development-history-and-technical-profiles.pdfIn PDF document text
    • http://www.gorillawalker.com/characteristics-of-the-bioreactor-landfill-system-using-an-anaerobic-aerobic.pdfIn PDF document text
    • http://www.gorillawalker.com/building-the-steam-navy-dockyards-technology-and-the-creation-of.pdfIn PDF document text
    • http://www.gorillawalker.com/let-s-review-earth-science-the-physical-setting.pdfIn PDF document text
    • http://www.gorillawalker.com/my-school-mi-escuela.pdfIn PDF document text
    • http://www.gorillawalker.com/popular-science.pdfIn PDF document text
    • http://www.gorillawalker.com/advanced-asic-chip-synthesis-using-synopsys-design-compiler-tm-physical.pdfIn PDF document text
    • http://www.gorillawalker.com/the-origin-of-wealth-the-radical-remaking-of-economics-and.pdfIn PDF document text
    • http://www.gorillawalker.com/nursing-research-principles-and-methods-7th-edition-black-cover.pdfIn PDF document text
    • http://www.gorillawalker.com/capital-wars-the-new-east-west-challenge-for-entrepreneurial-leadership.pdfIn PDF document text
    • http://www.gorillawalker.com/luther-s-works-lectures-on-isaiah-chapters-1-39.pdfIn PDF document text
    • http://www.gorillawalker.com/comprehensive-surgical-management-of-congenital-heart-disease-hodder-arnold-publication.pdfIn PDF document text
    • http://www.gorillawalker.com/eureka-math-a-story-of-functions-geometry-module-4-connecting.pdfIn PDF document text
    • http://www.gorillawalker.com/the-mountain-biker-s-guide-to-arizona-dennis-coello-s.pdfIn PDF document text
    • http://www.gorillawalker.com/before-i-go-to-sleep-a-novel-unabridged-audible-audio.pdfIn PDF document text
    • http://www.gorillawalker.com/preaching-with-spiritual-vigour-including-lessons-from-the-the-life.pdfIn PDF document text
    • http://www.gorillawalker.com/stop-smoking-with-cbt-the-most-powerful-way-to-beat.pdfIn PDF document text
    • http://www.gorillawalker.com/financial-risk-management-applications-in-market-credit-asset-and-liability.pdfIn PDF document text
    • http://www.gorillawalker.com/modern-governance-new-government-society-interactions.pdfIn PDF document text
    • http://www.gorillawalker.com/die-italienerin-in-algier-tredition-classics-german-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/the-book-of-alfalfa-history-cultivation-and-merits-its-uses.pdfIn PDF document text
    • http://www.gorillawalker.com/the-grove-encyclopedia-of-classical-art-architecture-2-volume-set.pdfIn PDF document text
    • http://www.gorillawalker.com/distant-signals.pdfIn PDF document text
    • http://www.gorillawalker.com/paskagankee-a-paskagankee-novel.pdfIn PDF document text
    • http://www.gorillawalker.com/anatomy-of-orofacial-structures-enhanced-7th-edition-pageburst-e-book.pdfIn PDF document text
    • http://www.gorillawalker.com/the-palestinian-refugees-in-jordan-1948-1957.pdfIn PDF document text
    • http://www.gorillawalker.com/the-path-of-reza-shah-the-great-persian-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/constitutional-law-in-context-volume-1-third-edition-carolina-academic.pdfIn PDF document text
    • http://www.gorillawalker.com/men-with-their-hands.pdfIn PDF document text
    • http://www.gorillawalker.com/practice-and-procedure-of-the-companies-court-lloyd-s-commercial.pdfIn PDF document text
    • http://www.gorillawalker.com/the-riddle-of-gender-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/the-diaries-of-hannah-cullwick-victorian-maidservant.pdfIn PDF document text
    • http://www.gorillawalker.com/give-me-your-answer-do-acting-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/military-and-sporting-rifle-shooting.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://www.freepdfconvert.comIn PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text