Malicious PDF — malware analysis report

Static analysis result for SHA-256 a86e72e227c52c58…

MALICIOUS

PDF

45.7 KB Created: 2019-04-08 09:01:00 +03:00 Authoring application: AH XSL Formatter V6.1 MR1 for Linux64 : 6.1.6.12100 (via Antenna House PDF Output Library 6.1.420 (Linux64); modified using iText 2.1.7 by 1T3XT)
MD5: 0d2ea34008bc5ba5ce069e6ff452fde3 SHA-1: 053bab1569dcd0a3123befd3c5878a82b5405f6a SHA-256: a86e72e227c52c584f0cd314bd08d78a7c24d5727a3fadff87c9d7b852ca5e42
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated and unreadable, the presence of numerous links to other PDF files suggests a link farm or a method to distribute malicious content. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be leveraging a large number of external links for a malicious purpose, potentially SEO manipulation or hosting further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8439

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/the-ghosts-of-autumn-a-season-of-hunting-stories.pdf
    • http://www.gorillawalker.com/sweet-robin-a-biography-of-robert-dudley-earl-of-leicester.pdf
    • http://www.gorillawalker.com/rock-climbing-colorado.pdf
    • http://www.gorillawalker.com/the-holy-bible-in-falam-chin-language-color-maps-revised.pdf
    • http://www.gorillawalker.com/alpine-sierra-trailblazer-where-to-hike-ski-bike-fish-and.pdf
    • http://www.gorillawalker.com/living-buildings-architectural-conservation-philosophy-principles-and-practice.pdf
    • http://www.gorillawalker.com/365-things-people-believe-that-aren-t-true-the-misconception.pdf
    • http://www.gorillawalker.com/amazon-echo-amazon-echo-user-manual-2nd-edition-tech-geek.pdf
    • http://www.gorillawalker.com/poptopics-mythology-1-poptropica.pdf
    • http://www.gorillawalker.com/hua-shuo-ren-min-bi-chinese-edition.pdf
    • http://www.gorillawalker.com/introduction-to-rf-and-microwave-passive-components.pdf
    • http://www.gorillawalker.com/dennis-the-menace-1-the-classic-comicbooks.pdf
    • http://www.gorillawalker.com/honda-cb550-and-650-1983-1985-service-repair-maintenance-clymer.pdf
    • http://www.gorillawalker.com/the-finished-work-of-christ-the-truth-of-romans-1.pdf
    • http://www.gorillawalker.com/microsoft-outlook-2010-introductory-sam-2010-compatible-products.pdf
    • http://www.gorillawalker.com/dive-the-bahamas-complete-guide-to-diving-and-snorkelling-interlink.pdf
    • http://www.gorillawalker.com/secret-of-mental-math-arithmetic-70-secrets-to-super-speed.pdf
    • http://www.gorillawalker.com/le-quebec-2013-7x7-mini-wall-french-edition.pdf
    • http://www.gorillawalker.com/preventative-maintenance-for-multi-family-housing-for-apartment-communities-condominium.pdf
    • http://www.gorillawalker.com/rudder-from-leader-to-legend-centennial-series-of-the-association.pdf
    • http://www.gorillawalker.com/garden-planner-your-personal-garden-planner-office-equipment-supplies-for.pdf
    • http://www.gorillawalker.com/quality-is-free-the-art-of-making-quality-certain-how.pdf
    • http://www.gorillawalker.com/colombo-s-hollywood-wit-and-wisdom-of-the-moviemakers.pdf
    • http://www.gorillawalker.com/an-elephant-family-adventure-the-elephants-tour-england.pdf
    • http://www.gorillawalker.com/on-the-philosophy-of-logic-wadsworth-philosophical-topics.pdf
    • http://www.gorillawalker.com/hesburgh-a-biography.pdf
    • http://www.gorillawalker.com/the-cambridge-history-of-australian-literature.pdf
    • http://www.gorillawalker.com/klepto.pdf
    • http://www.gorillawalker.com/big-sam-my-autobiography.pdf
    • http://www.gorillawalker.com/intro-to-statistical-signal-procing-the-aksen-associates-series-in.pdf
    • http://www.gorillawalker.com/essays-on-cuban-music-north-american-and-cuban-perspectives.pdf
    • http://www.gorillawalker.com/arms-of-little-value-the-challenge-of-insurgency-and-global.pdf
    • http://www.gorillawalker.com/traditional-japanese-fashions-paper-dolls-dover-paper-dolls.pdf
    • http://www.gorillawalker.com/caa-region-3-northern-ireland.pdf
    • http://www.gorillawalker.com/key-insights-from-winning-blinkist-summaries-book-9-kindle-edition.pdf
    • http://www.gorillawalker.com/beverly-cleary-united-states-authors-series.pdf
    • http://www.gorillawalker.com/meaning-agency-and-colonial-history-navosavakadua-and-the-tuka-movement.pdf
    • http://www.gorillawalker.com/learn-to-play-go-vol-5-the-palace-of-memory.pdf
    • http://www.gorillawalker.com/equilibrium-unemployment-theory-2nd-edition.pdf
    • http://www.gorillawalker.com/nat-rliche-menopause.pdf
    • http://www.gorillawalker.com/alpine-sierra-trailblazer-where-to-hike-s
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/