Malicious PDF — malware analysis report

Static analysis result for SHA-256 a615a0e2c843ae97…

MALICIOUS

PDF

33.2 KB Created: 2019-10-29 07:56:00 +03:00 Authoring application: FrameMaker 10.0.2 (via Acrobat Distiller 11.0 (Windows))
MD5: f809acce014364de75009fc90eb40731 SHA-1: 379418a6f5c352267b50e03db3c2488f5a8dc5ea SHA-256: a615a0e2c843ae972acfd8fa5f4d4cb836a1741d136b618b525979f2a234c65c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged the document as malicious. The primary attack pattern appears to be SEO manipulation or a link farm designed to drive traffic to a website hosting numerous PDF documents, potentially as a distribution vector for further malicious content or to manipulate search engine rankings.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8529

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/african-swine-fever-virus-virology-monographs.pdf
    • http://www.gorillawalker.com/microprocessor-architecture-programming-and-applications-with-the-8085-5th-edition.pdf
    • http://www.gorillawalker.com/the-anytime-bible.pdf
    • http://www.gorillawalker.com/airbrushing-basics.pdf
    • http://www.gorillawalker.com/the-river-bank-and-other-stories-from-the-wind-in.pdf
    • http://www.gorillawalker.com/the-arrest-of-ships-in-private-international-law-oxford-private.pdf
    • http://www.gorillawalker.com/effective-home-birth-preparation-self-hypnosis.pdf
    • http://www.gorillawalker.com/eliza-visits-martha-s-vineyard.pdf
    • http://www.gorillawalker.com/poolside-sudoku.pdf
    • http://www.gorillawalker.com/50-rules-kids-won-t-learn-in-school-real-world.pdf
    • http://www.gorillawalker.com/concepts-of-disability-income-insurance-kindle-edition.pdf
    • http://www.gorillawalker.com/mastering-autodesk-revit-architecture-2011.pdf
    • http://www.gorillawalker.com/code-of-federal-regulations-title-12-parts-600-899-bank.pdf
    • http://www.gorillawalker.com/encyclopedia-of-freemasonry-m-z.pdf
    • http://www.gorillawalker.com/cuentos-latinoamericanos-spanish-edition.pdf
    • http://www.gorillawalker.com/psychiatric-medication-issues-for-social-workers-counselors-and-psychologists.pdf
    • http://www.gorillawalker.com/better-homes-and-gardens-365-vegetarian-meals.pdf
    • http://www.gorillawalker.com/the-perfect-formula-diet-how-to-lose-weight-and-get.pdf
    • http://www.gorillawalker.com/myth-religion-and-society.pdf
    • http://www.gorillawalker.com/what-a-catch-northwest-territories-pike-wolf-of-the-north.pdf
    • http://www.gorillawalker.com/anvil-tax-guide-an-ex-irs-auditor-s-tips-to.pdf
    • http://www.gorillawalker.com/a-hacker-never-has-a-bad-lie-true-golf-stories.pdf
    • http://www.gorillawalker.com/the-play-s-the-thing-strategic-creativity-series.pdf
    • http://www.gorillawalker.com/football-traumatology-new-trends.pdf
    • http://www.gorillawalker.com/critical-aesthetics-and-postmodernism.pdf
    • http://www.gorillawalker.com/simple-and-easy-japanese-cooking.pdf
    • http://www.gorillawalker.com/the-elements-of-expression-putting-thoughts-into-words-revised-and.pdf
    • http://www.gorillawalker.com/golden-filly-collection-1.pdf
    • http://www.gorillawalker.com/asymmetric-sailing.pdf
    • http://www.gorillawalker.com/my-kind-of-crazy-living-in-a-bipolar-world-kindle.pdf
    • http://www.gorillawalker.com/global-pseudo-differential-calculus-on-euclidean-spaces-pseudo-differential-operators.pdf
    • http://www.gorillawalker.com/fossils-a-guide-to-prehistoric-life.pdf
    • http://www.gorillawalker.com/urban-ecology-an-international-perspective-on-the-interaction-between-humans.pdf
    • http://www.gorillawalker.com/alquimia-fria-dry-martini-historias-leyendas-y-recetas-originales-spanish.pdf
    • http://www.gorillawalker.com/technical-manual-test-set-aviator-s-night-vision-imaging-system.pdf
    • http://www.gorillawalker.com/cal-98-it-s-the-life-in-hell-13-month.pdf
    • http://www.gorillawalker.com/chemical-tank-lines-inc-v-holstine-edward-u-s-supreme.pdf
    • http://www.gorillawalker.com/habits-of-sin.pdf
    • http://www.gorillawalker.com/endangered-species-korean-edition.pdf
    • http://www.gorillawalker.com/the-few-fight-for-the-skies-images-of-war.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/