Malicious PDF — malware analysis report

Static analysis result for SHA-256 abb2030a4b119d02…

MALICIOUS

PDF

35.5 KB Created: 2020-02-20 04:52:52 +03:00 Authoring application: Pscript.dll Version 5.0 (via AFPL Ghostscript 8.50) First seen: 2021-06-28
MD5: b2917368874b660212bed1fa90ffe228 SHA-1: b9355a7f8f9800ab071c1bf95868532d2ed9af92 SHA-256: abb2030a4b119d02612fca4eb06b96fc9e1a9dfe68e010c862432a360d3b9dfb
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. These links all point to the same domain, suggesting a coordinated effort to manipulate search engine results or distribute content. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine a more specific intent beyond link distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8018

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/how-to-know-the-freshwater-algae.pdf In PDF document text
    • http://www.gorillawalker.com/ion-exchange-column-modeling-of-borates-for-a-multicomponent-system.pdfIn PDF document text
    • http://www.gorillawalker.com/tackling-cancer-scientific-american-cutting-edge-science.pdfIn PDF document text
    • http://www.gorillawalker.com/a-taste-of-memories-from-the-old-bush-vol-2.pdfIn PDF document text
    • http://www.gorillawalker.com/mel-bay-more-fun-with-the-saxophone.pdfIn PDF document text
    • http://www.gorillawalker.com/steuben-and-turnier-s-problems-in-the-fundamentals-of-federal.pdfIn PDF document text
    • http://www.gorillawalker.com/one-basket-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/concepts-of-computational-finite-elements-and-methods-of-static-and.pdfIn PDF document text
    • http://www.gorillawalker.com/masteringmicrobiology-with-pearson-etext-standalone-access-card-for-microbiology-an.pdfIn PDF document text
    • http://www.gorillawalker.com/living-college-life-in-the-front-row.pdfIn PDF document text
    • http://www.gorillawalker.com/cocina-diaria-en-olla-de-cocimiento-lento-everyday-slow-cooking.pdfIn PDF document text
    • http://www.gorillawalker.com/a-modern-reiki-method-for-healing.pdfIn PDF document text
    • http://www.gorillawalker.com/sunrise-serenade-sheet-music-for-voice-and-piano-with-guitar.pdfIn PDF document text
    • http://www.gorillawalker.com/packaging-research-in-food-product-design-and-development.pdfIn PDF document text
    • http://www.gorillawalker.com/the-ciba-collection-of-medical-illustrations-vol-1.pdfIn PDF document text
    • http://www.gorillawalker.com/sea-warfare.pdfIn PDF document text
    • http://www.gorillawalker.com/henry-vi-part-two-oxford-world-s-classics-pt-2.pdfIn PDF document text
    • http://www.gorillawalker.com/student-solutions-manual-for-winston-s-introduction-to-mathematical-programming.pdfIn PDF document text
    • http://www.gorillawalker.com/mama-cat-s-adventures-in-child-training-presents-no-whining.pdfIn PDF document text
    • http://www.gorillawalker.com/striking-a-balance.pdfIn PDF document text
    • http://www.gorillawalker.com/between-field-and-cooking-pot-the-political-economy-of-marketwomen.pdfIn PDF document text
    • http://www.gorillawalker.com/quantum-mechanics-of-one-and-two-electron-atoms.pdfIn PDF document text
    • http://www.gorillawalker.com/communicating-across-dementia-how-to-talk-listen-provide-stimulation-and.pdfIn PDF document text
    • http://www.gorillawalker.com/dave-sim-s-last-girlfriend.pdfIn PDF document text
    • http://www.gorillawalker.com/iraq-the-moral-reckoning.pdfIn PDF document text
    • http://www.gorillawalker.com/surf-survival-the-surfer-s-health-handbook-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/telling-the-story-a-passover-haggadah-explained.pdfIn PDF document text
    • http://www.gorillawalker.com/books-hot-off-the-press-ff-you-re-looking-for.pdfIn PDF document text
    • http://www.gorillawalker.com/handbook-of-clinical-hypnosis-dissociation-trauma-memory-and-hypnosis.pdfIn PDF document text
    • http://www.gorillawalker.com/a-gathering-of-days-a-new-england-girl-s-journal.pdfIn PDF document text
    • http://www.gorillawalker.com/phoenix-rising-1-elissa-s-quest-phoenix-rising-trilogy.pdfIn PDF document text
    • http://www.gorillawalker.com/vigorrobic-the-training-plan-to-boost-your-sex-life.pdfIn PDF document text
    • http://www.gorillawalker.com/wampeters-foma-granfalloons-opinions.pdfIn PDF document text
    • http://www.gorillawalker.com/swear.pdfIn PDF document text
    • http://www.gorillawalker.com/bigfoot-needs-milk-lactation-monster-erotica.pdfIn PDF document text
    • http://www.gorillawalker.com/100-years-of-the-isle-of-man-tt-a-century.pdfIn PDF document text
    • http://www.gorillawalker.com/the-geomancer-vampire-empire-a-gareth-and-adele-novel.pdfIn PDF document text
    • http://www.gorillawalker.com/learning-from-experience.pdfIn PDF document text
    • http://www.gorillawalker.com/aceh-history-politics-and-culture.pdfIn PDF document text
    • http://www.gorillawalker.com/the-stewardship-companion-lectionary-resources-for-preaching.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text