Malicious PDF — malware analysis report

Static analysis result for SHA-256 9aa93cf7a229ecc5…

MALICIOUS

PDF

35.0 KB Created: 2019-12-09 21:31:15 +03:00 Authoring application: Adobe Acrobat 8.0 (via Adobe Acrobat 8.0 Image Conversion Plug-in)
MD5: 0cebd1ff31539975ee4d6a90059d6c21 SHA-1: 2a9e36e0dc03cc17e4aa35599427a6c5c8994a34 SHA-256: 9aa93cf7a229ecc56bca99cf64f023a3886f5847a12515f0d241f7bcb001af45
130 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to other PDFs on the same domain, identified as a 'PDF_SEO_LINK_FARM'. The 'SE_ADVANCE_FEE_SCAM_LURE' heuristic indicates the document's content is designed to trick users into believing they are involved in a lottery, prize, or parcel delivery scam, which is a common tactic for advance-fee fraud. The ML classifier also flagged the PDF as malicious with a high score. The primary attack pattern involves directing users to a link farm, likely to facilitate further malicious activity or scams.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8531

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/dimensions-of-non-commercial-foodservice-management-hospitality-travel-tourism.pdf
    • http://www.gorillawalker.com/the-best-in-scuba-diving.pdf
    • http://www.gorillawalker.com/infinity-chronicles-of-nick-large-print-hardcover.pdf
    • http://www.gorillawalker.com/combust-the-sun-richfield-rivers-mystery-series.pdf
    • http://www.gorillawalker.com/sip-away-your-wrinkles-look-younger-at-any-age-kindle.pdf
    • http://www.gorillawalker.com/ethics-and-science-an-introduction-cambridge-applied-ethics.pdf
    • http://www.gorillawalker.com/tigger-on-the-couch-the-neuroses-psychoses-disorders-and-maladies.pdf
    • http://www.gorillawalker.com/fat-city-and-urban-ice-a-climbers-guide-to-the.pdf
    • http://www.gorillawalker.com/simeon-anna-s-christmas-bauble-books.pdf
    • http://www.gorillawalker.com/me-and-the-orgone-one-man-s-sexual-revolution.pdf
    • http://www.gorillawalker.com/plunkett-s-infotech-industry-almanac-2008-infotech-industry-market-research.pdf
    • http://www.gorillawalker.com/microbeam-analysis-1995-proceedings-of-the-29th-annual-conference-of.pdf
    • http://www.gorillawalker.com/java-quick-reference.pdf
    • http://www.gorillawalker.com/the-tale-of-troy-library-edition.pdf
    • http://www.gorillawalker.com/reading-comprehension-essays-gre-preparation-guide-1st-edition-manhattan-gre.pdf
    • http://www.gorillawalker.com/pandora-hearts-vol-5.pdf
    • http://www.gorillawalker.com/encyclopedia-of-continental-army-units-battalions-regiments-and-independent-corps.pdf
    • http://www.gorillawalker.com/garibaldi-and-the-thousand.pdf
    • http://www.gorillawalker.com/how-to-be-a-poker-player-the-philosophy-of-poker.pdf
    • http://www.gorillawalker.com/the-nonprofit-outcomes-toolbox-a-complete-guide-to-program-effectiveness.pdf
    • http://www.gorillawalker.com/a-2d-switched-reluctance-planar-motor.pdf
    • http://www.gorillawalker.com/cancer-stem-cells-methods-and-protocols-methods-in-molecular-biology.pdf
    • http://www.gorillawalker.com/2010-oncology-nursing-drug-handbook.pdf
    • http://www.gorillawalker.com/fishcamp-life-on-an-alaskan-shore.pdf
    • http://www.gorillawalker.com/doorway-thoughts-cross-cultural-health-care-for-older-adults-volume.pdf
    • http://www.gorillawalker.com/how-to-read-maps.pdf
    • http://www.gorillawalker.com/criminal-law-and-procedure-5th-fifth-edition-text-only.pdf
    • http://www.gorillawalker.com/winning-lotto-lottery-for-the-everyday-player-kindle-edition.pdf
    • http://www.gorillawalker.com/i-see-a-red-door-a-novel.pdf
    • http://www.gorillawalker.com/theater-design-second-edition.pdf
    • http://www.gorillawalker.com/solar-energy-the-sleeping-giant-basics-of-solar-energy.pdf
    • http://www.gorillawalker.com/brainfood-doodle-mats-u-s-a.pdf
    • http://www.gorillawalker.com/baby-hippos-blastoff-readers-level-1.pdf
    • http://www.gorillawalker.com/spatial-simulation-exploring-pattern-and-process.pdf
    • http://www.gorillawalker.com/hidden-victims-the-effects-of-the-death-penalty-on-families.pdf
    • http://www.gorillawalker.com/cervantes-s-novelas-ejemplares-reading-their-lessons-from-his-time.pdf
    • http://www.gorillawalker.com/hollywood-femmes-fatales-volume-2-hollywood-femmes-fatales-and-divas.pdf
    • http://www.gorillawalker.com/sex-health-and-long-life-manuals-of-taoist-practice.pdf
    • http://www.gorillawalker.com/european-competition-law-annual-2013-effective-and-legitimate-enforcement-of.pdf
    • http://www.gorillawalker.com/botham-s-century.pdf
    • http://www.gorillawalker.com/me
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/