Malicious PDF — malware analysis report

Static analysis result for SHA-256 92c47d2cc1a3a4e9…

MALICIOUS

PDF

45.0 KB Created: 2019-03-17 11:20:37 +03:00 Authoring application: FrameMaker 7.0 (via Acrobat Distiller 5.0.5 (Windows))
MD5: 747fba6b4d98c77cd504b9942238747d SHA-1: d361270ba10cf61ad95337557a742be12d0ea7f1 SHA-256: 92c47d2cc1a3a4e9b4bad843a9bf5906d148173045c5f8e4493be2029a57f152
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a large number of external PDF links, all hosted on the domain 'www.gorillawalker.com'. This suggests a link farm or SEO manipulation tactic. The embedded URLs point to various PDF documents, indicating a potential distribution or redirection mechanism. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/our-baby-rowan-the-story-of-our-baby-boy-rowan.pdf
    • http://www.gorillawalker.com/the-play-of-words-fun-games-for-language-lovers.pdf
    • http://www.gorillawalker.com/scientific-english-a-guide-for-scientists-and-other-professionals.pdf
    • http://www.gorillawalker.com/study-guide-to-accompany-racial-and-ethnic-groups-11th-edition.pdf
    • http://www.gorillawalker.com/toddler-story-book-rory-and-the-lion.pdf
    • http://www.gorillawalker.com/rigby-on-our-way-to-english-bookroom-package-grade-4.pdf
    • http://www.gorillawalker.com/children-in-prehistoric-puebloan-southwest.pdf
    • http://www.gorillawalker.com/english-authors-series-william-shakespeare-the-tragedies-twayne-s-english.pdf
    • http://www.gorillawalker.com/genocide-collective-violence-and-popular-memory-the-politics-of-remembrance.pdf
    • http://www.gorillawalker.com/the-south-beach-heart-health-revolution-cardiac-prevention-that-can.pdf
    • http://www.gorillawalker.com/tm-3-34-44-fm-5-428-mcrp-3-17.pdf
    • http://www.gorillawalker.com/saunders-solutions-in-veterinary-practice-small-animal-gastroenterology-1e.pdf
    • http://www.gorillawalker.com/entering-the-frame-cinema-and-history-in-the-films-of.pdf
    • http://www.gorillawalker.com/single-variable-calculus-early-transcendentals-volume-1-6th-sixth-edition.pdf
    • http://www.gorillawalker.com/seafood-chilling-refrigeration-and-freezing-science-and-technology.pdf
    • http://www.gorillawalker.com/letitia-landon-and-romantic-hellenism-william-wordsworth-critical-essay-an.pdf
    • http://www.gorillawalker.com/ak-handbook-ak47-akm-ak74-an-operational-guide-to-the.pdf
    • http://www.gorillawalker.com/the-principal-from-the-black-lagoon.pdf
    • http://www.gorillawalker.com/internet-explorer-11-for-windows-8-1-quick-reference-guide.pdf
    • http://www.gorillawalker.com/faith-filled-lullabies-with-big-al-and-annie-hardcover.pdf
    • http://www.gorillawalker.com/report-on-the-relativity-theory-of-gravitation-dover-phoenix-editions.pdf
    • http://www.gorillawalker.com/bacteriological-and-immunological-aspects-of-psoriasis-evidence-for-superantigenic-staphylococcal.pdf
    • http://www.gorillawalker.com/cultural-competency-for-health-administration-and-public-health.pdf
    • http://www.gorillawalker.com/all-in-one-bible-fun-favorite-bible-stories-preschool.pdf
    • http://www.gorillawalker.com/mexican-flavors-contemporary-recipes-from-camp-san-miguel.pdf
    • http://www.gorillawalker.com/my-florida-alphabet.pdf
    • http://www.gorillawalker.com/figuras-ensename-board-books.pdf
    • http://www.gorillawalker.com/antisemitism-through-the-ages-studies-in-antisemitism-series.pdf
    • http://www.gorillawalker.com/el-gran-libro-de-autocad-2008-spanish-edition.pdf
    • http://www.gorillawalker.com/knowing-god-kindle-edition.pdf
    • http://www.gorillawalker.com/warlord-of-mars-volume-2-tp.pdf
    • http://www.gorillawalker.com/hot-erotica-collection.pdf
    • http://www.gorillawalker.com/danger-at-thatcham-hall.pdf
    • http://www.gorillawalker.com/the-cloud-and-the-fire.pdf
    • http://www.gorillawalker.com/astrology-for-beginners-an-easy-guide-to-understanding-interpreting-your.pdf
    • http://www.gorillawalker.com/crucial-conversations-tools-for-talking-when-stakes-are-high-second.pdf
    • http://www.gorillawalker.com/senior-fitness-test-manual.pdf
    • http://www.gorillawalker.com/sand-casting-concrete-five-easy-projects.pdf
    • http://www.gorillawalker.com/vital-questions-facing-disability-studies-in-education.pdf
    • http://www.gorillawalker.com/power-base-selling-secrets-of-an-ivy-league-street-fighter.pdf
    • http://www.gorillawalker.com/rigb
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/