Malicious PDF — malware analysis report

Static analysis result for SHA-256 9a78f749f84dc0bc…

MALICIOUS

PDF

42.5 KB Created: 2018-11-30 20:31:44 +03:00 Authoring application: - (via Acrobat Distiller 3.0 for Power Macintosh)
MD5: ae77d8412c61d1c574553b39356eb25d SHA-1: 4d3c9b30f9e9909543eb77ff0ebfec1ca86b8769 SHA-256: 9a78f749f84dc0bcc46bae64d8c3fd786074b41070a1e7d3988c5e724d6d4eb3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this file as malicious. The primary purpose appears to be directing users to a large collection of PDFs hosted on gorillawalker.com, potentially for SEO manipulation or to serve as a distribution point for other malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9027

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/dyslexia-and-early-childhood-an-essential-guide-to-theory-and.pdf
    • http://www.gorillawalker.com/strategic-fixed-income-investment.pdf
    • http://www.gorillawalker.com/haystack-syndrome.pdf
    • http://www.gorillawalker.com/the-aishes-chayil-song-discover-how-each-verse-illuminates-a.pdf
    • http://www.gorillawalker.com/the-hashemite-kingdom-of-jordan-a-peace-corps-publication.pdf
    • http://www.gorillawalker.com/political-theory-and-australian-multuiculturalism.pdf
    • http://www.gorillawalker.com/duo-sonata-for-two-bassoons-score-and-parts.pdf
    • http://www.gorillawalker.com/convierta-su-casa-en-una-alcanc-a-spanish-edition.pdf
    • http://www.gorillawalker.com/the-vanishing-new-jersey-landscape.pdf
    • http://www.gorillawalker.com/right-to-the-top-port-hope-simpson-mysteries-volume-7.pdf
    • http://www.gorillawalker.com/technology-and-society-under-lenin-and-stalin-origins-of-the.pdf
    • http://www.gorillawalker.com/alpine-renault-the-sports-prototypes-1973-to-1978.pdf
    • http://www.gorillawalker.com/mcgraw-hill-s-top-50-skills-for-a-top-score.pdf
    • http://www.gorillawalker.com/en-espa-ol-pupil-edition-w-eedition-cd-rom-level.pdf
    • http://www.gorillawalker.com/savitri-op25-study-score-edition-eulenburg.pdf
    • http://www.gorillawalker.com/potato-a-tale-from-the-great-depression.pdf
    • http://www.gorillawalker.com/towards-democracy.pdf
    • http://www.gorillawalker.com/operating-systems-design-and-implementation-prentice-hall-software-series.pdf
    • http://www.gorillawalker.com/cool-hotels-spa-wellness.pdf
    • http://www.gorillawalker.com/auld-lang-syne-the-story-of-scotland-s-most-famous.pdf
    • http://www.gorillawalker.com/ukraine-2014-reise-2440.pdf
    • http://www.gorillawalker.com/dr-drowsy-s-sleep-prescription.pdf
    • http://www.gorillawalker.com/los-a-os-de-la-guerra-spanish-edition.pdf
    • http://www.gorillawalker.com/a-personality-disorder-something-kodansha-gendaishinsho-2012-isbn-4062881802-japanese.pdf
    • http://www.gorillawalker.com/lonely-planet-discover-california-travel-guide.pdf
    • http://www.gorillawalker.com/street-girl-workhouse-girl.pdf
    • http://www.gorillawalker.com/learning-web-app-development.pdf
    • http://www.gorillawalker.com/thrifty-cook-main-meals-two-another-month-s-worth-of.pdf
    • http://www.gorillawalker.com/the-ant-trap-rebuilding-the-foundations-of-the-social-sciences.pdf
    • http://www.gorillawalker.com/workbook-for-keys-to-teaching-grammar-to-english-language-learners.pdf
    • http://www.gorillawalker.com/snowthrower-service-ed-3.pdf
    • http://www.gorillawalker.com/matters-of-life-and-longing-female-sterilisation-in-northeast-brazil.pdf
    • http://www.gorillawalker.com/the-blackwell-guide-to-mill-s-utilitarianism.pdf
    • http://www.gorillawalker.com/black-gold-of-the-sun.pdf
    • http://www.gorillawalker.com/clinical-management-of-the-osteoporoses-unknown-binding.pdf
    • http://www.gorillawalker.com/young-gifted-and-bad-a-sweets-maybrey-novel-volume-2.pdf
    • http://www.gorillawalker.com/justice-while-black-helping-african-american-families-navigate-and-survive.pdf
    • http://www.gorillawalker.com/come-into-my-kitchen-old-world-armenian-recipes-and-international.pdf
    • http://www.gorillawalker.com/the-story-of-disney-built-for-success.pdf
    • http://www.gorillawalker.com/adventures-of-the-soul-journeys-through-the-physical-and-spiritual.pdf
    • http://www.gorillawalker.com/political-theory-
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/