Malicious PDF — malware analysis report

Static analysis result for SHA-256 a4ed5a519b98c6ab…

MALICIOUS

PDF

40.8 KB Created: 2019-03-17 11:33:25 +03:00 Authoring application: FrameMaker 7.0 (via Acrobat Distiller 5.0.5 (Windows); modified using iText® 5.5.4 ©2000-2014 iText Group NV (AGPL-version)) First seen: 2020-12-28
MD5: 0115d641fccd2aa33ed3da3dce4453af SHA-1: 72de80283aaee18cef0c97b26b773fa1a2df022c SHA-256: a4ed5a519b98c6abb76f7ea06888fcf17be1a7249cf43a7b54fadd0b98838aaf
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files on the domain 'gorillawalker.com'. This is indicative of a link farm or a distribution mechanism for other malicious content. The ML classifier also flagged the document as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8872

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/the-story-of-ferdinand-75th-anniversary-edition.pdf In PDF document text
    • http://www.gorillawalker.com/cooking-without-salt-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/evolutionary-mechanisms-of-defense-reactions-advances-in-life-sciences.pdfIn PDF document text
    • http://www.gorillawalker.com/my-two-chinas-the-memoir-of-a-chinese-counterrevolutionary.pdfIn PDF document text
    • http://www.gorillawalker.com/absolutely-invincible-gemini-books.pdfIn PDF document text
    • http://www.gorillawalker.com/left-on-the-labrador.pdfIn PDF document text
    • http://www.gorillawalker.com/floral-design-dover-pictura-electronic-clip-art.pdfIn PDF document text
    • http://www.gorillawalker.com/the-prevention-of-aging-alzheimers-and-stroke-brain-matters.pdfIn PDF document text
    • http://www.gorillawalker.com/paleoanthropology-world-anthropology.pdfIn PDF document text
    • http://www.gorillawalker.com/the-art-detective-fakes-frauds-and-finds-and-the-search.pdfIn PDF document text
    • http://www.gorillawalker.com/an-unauthorized-guide-to-tv-s-scorpion-the-international-political.pdfIn PDF document text
    • http://www.gorillawalker.com/boats-ships-submarines-and-other-floating-machines-how-things-work.pdfIn PDF document text
    • http://www.gorillawalker.com/women-s-health-care-handbook.pdfIn PDF document text
    • http://www.gorillawalker.com/more-kinds-of-being-a-further-study-of-individuation-identity.pdfIn PDF document text
    • http://www.gorillawalker.com/prepper-s-hacks-box-set-96-brilliant-surviving-hacks-top.pdfIn PDF document text
    • http://www.gorillawalker.com/journey-into-mystery-vol-3-terrorism-myth.pdfIn PDF document text
    • http://www.gorillawalker.com/macaroni-cheese-52-recipes-from-simple-to-sublime.pdfIn PDF document text
    • http://www.gorillawalker.com/managing-conflict-with-your-boss.pdfIn PDF document text
    • http://www.gorillawalker.com/sacred-sound-mantra-meditations-for-centredness-and-inspiration-2-cds.pdfIn PDF document text
    • http://www.gorillawalker.com/psychonauts-official-strategy-guide.pdfIn PDF document text
    • http://www.gorillawalker.com/people-in-watercolour-collins-30-minute-painting-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/vegetable-production-and-practices.pdfIn PDF document text
    • http://www.gorillawalker.com/100-adornos-para-pasteles-curso-de-modelado-en-az-car.pdfIn PDF document text
    • http://www.gorillawalker.com/the-food-of-indonesia-delicious-recipes-from-bali-java-and.pdfIn PDF document text
    • http://www.gorillawalker.com/him.pdfIn PDF document text
    • http://www.gorillawalker.com/soil-science-simplified-4th-fourth-edition-text-only.pdfIn PDF document text
    • http://www.gorillawalker.com/el-t-nel-novela-esenciales-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/managing-time.pdfIn PDF document text
    • http://www.gorillawalker.com/propellerhead-record-ignite-the-visual-guide-for-new-users.pdfIn PDF document text
    • http://www.gorillawalker.com/understanding-the-equine-foot-the-horse-care-health-care-library.pdfIn PDF document text
    • http://www.gorillawalker.com/thinking-critically-about-ethical-issues.pdfIn PDF document text
    • http://www.gorillawalker.com/think-speak-win-discover-the-art-of-debate.pdfIn PDF document text
    • http://www.gorillawalker.com/algebra-1-6-dvds-workbook-dvd-rom.pdfIn PDF document text
    • http://www.gorillawalker.com/101-checker-puzzles-mensa.pdfIn PDF document text
    • http://www.gorillawalker.com/the-scottish-legacy.pdfIn PDF document text
    • http://www.gorillawalker.com/las-flores-flowers-plantas-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/diamond-mind-a-psychology-of-meditation.pdfIn PDF document text
    • http://www.gorillawalker.com/great-word-search-puzzles-for-kids.pdfIn PDF document text
    • http://www.gorillawalker.com/mumbai-and-goa-travel-pack-globetrotter-travel-packs.pdfIn PDF document text
    • http://www.gorillawalker.com/drg-expert-2010-edition-compact.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text