Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba29fa9059e6515a…

MALICIOUS

PDF

41.8 KB Created: 2019-03-17 10:46:29 +03:00 Authoring application: XEP 4.4 build 20050610 First seen: 2021-06-20
MD5: 33bc762308562815808fcf323622d6ae SHA-1: 32cc9b916c3006cdc0ff6a6edff94586df35c954 SHA-256: ba29fa9059e6515ac80de085b15446457f11f2d29a96ecb26c02b38f6547cc64
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files on the domain 'gorillawalker.com'. This is indicative of a link farm, likely for SEO manipulation or to serve as a distribution point for further malicious content. The ML classifier also flagged this PDF as malicious. No scripts were extracted, but the presence of embedded URLs suggests a potential for malicious redirection or content delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9181

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/god-ain-t-worth-a-dime.pdf In PDF document text
    • http://www.gorillawalker.com/mythes-et-usages-des-mythes-autochtonie-et-id-ologie-de.pdfIn PDF document text
    • http://www.gorillawalker.com/attentional-capture-a-special-issue-of-visual-cognition.pdfIn PDF document text
    • http://www.gorillawalker.com/serpentine-enigma.pdfIn PDF document text
    • http://www.gorillawalker.com/the-peace-proxy.pdfIn PDF document text
    • http://www.gorillawalker.com/betting-game-orca-sports.pdfIn PDF document text
    • http://www.gorillawalker.com/medifocus-guidebook-on-spondylolisthesis.pdfIn PDF document text
    • http://www.gorillawalker.com/concorde-a-photographic-tribute.pdfIn PDF document text
    • http://www.gorillawalker.com/marsupials-and-politics-two-comedies-contemporary-australian-plays.pdfIn PDF document text
    • http://www.gorillawalker.com/the-firewood-collector-a-play-from-the-chinese-yuan-dynasty.pdfIn PDF document text
    • http://www.gorillawalker.com/the-bound-for-college-guidebook-a-step-by-step-guide.pdfIn PDF document text
    • http://www.gorillawalker.com/the-demon-wore-chains-gay-supernatural-erotica-celestial-bondage-book.pdfIn PDF document text
    • http://www.gorillawalker.com/star-wars-the-crimson-empire-saga.pdfIn PDF document text
    • http://www.gorillawalker.com/pastoral-power-beyond-psychology-s-marginalization-resisting-the-discourses-of.pdfIn PDF document text
    • http://www.gorillawalker.com/pink-ladies-crimson-gents-portraits-and-legends-of-50-roses.pdfIn PDF document text
    • http://www.gorillawalker.com/meta-perception-for-pathological-personality-traits-do-we-know-when.pdfIn PDF document text
    • http://www.gorillawalker.com/principles-of-color-a-review-of-past-traditions-and-modern.pdfIn PDF document text
    • http://www.gorillawalker.com/complete-linebacking.pdfIn PDF document text
    • http://www.gorillawalker.com/the-eye-of-the-moon.pdfIn PDF document text
    • http://www.gorillawalker.com/fundamentals-of-fluid-film-lubrication.pdfIn PDF document text
    • http://www.gorillawalker.com/texas-mountains.pdfIn PDF document text
    • http://www.gorillawalker.com/barbarian-chicks-demons-vol-4.pdfIn PDF document text
    • http://www.gorillawalker.com/the-unexpected-zombie.pdfIn PDF document text
    • http://www.gorillawalker.com/an-accident-waiting-to-happen-open-door.pdfIn PDF document text
    • http://www.gorillawalker.com/lure-encyclopedia.pdfIn PDF document text
    • http://www.gorillawalker.com/2d-autocad-for-students.pdfIn PDF document text
    • http://www.gorillawalker.com/greece-and-cyprus-1986-a-yearbook.pdfIn PDF document text
    • http://www.gorillawalker.com/the-resurgence-of-the-latin-american-left.pdfIn PDF document text
    • http://www.gorillawalker.com/messerschmitt-bf-109-living-legend.pdfIn PDF document text
    • http://www.gorillawalker.com/letters-and-papers-foreign-and-domestic-of-the-reign-of.pdfIn PDF document text
    • http://www.gorillawalker.com/game-theory-a-nontechnical-introduction-to-the-analysis-of-strategy.pdfIn PDF document text
    • http://www.gorillawalker.com/group-decision-making-under-multiple-criteria-methods-and-applications-lecture.pdfIn PDF document text
    • http://www.gorillawalker.com/classical-music-growing-minds-with-music-12.pdfIn PDF document text
    • http://www.gorillawalker.com/broken-hart-the-hart-family-book-1.pdfIn PDF document text
    • http://www.gorillawalker.com/my-best-friend-her-husband-and-my-birthday-an-ffm.pdfIn PDF document text
    • http://www.gorillawalker.com/sequencing-grade-2-practice-makes-perfect-teacher-created-materials.pdfIn PDF document text
    • http://www.gorillawalker.com/channel-islands-insight-guides.pdfIn PDF document text
    • http://www.gorillawalker.com/hello-mother-hello-father-celebrating-summer-camp.pdfIn PDF document text
    • http://www.gorillawalker.com/combat-and-survival-what-it-takes-to-fight-and-win.pdfIn PDF document text
    • http://www.gorillawalker.com/a-practical-guide-for-translators-topics-in-translation.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text