Malicious PDF — malware analysis report

Static analysis result for SHA-256 bdfd72653f83e046…

MALICIOUS

PDF

33.1 KB Created: 2019-12-29 00:08:21 +03:00 Authoring application: TeXmacs-1.0.7.3 (via GPL Ghostscript 8.70) First seen: 2021-06-28
MD5: 58c24d3ffca8998a78de4409837cb2af SHA-1: 8b2e7ab6acf59fa25f49d8971d836c38c238ff2f SHA-256: bdfd72653f83e046d3969e72c6b67d274a546c4df6eee3efa3dc390e93796d0e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files on the domain 'gorillawalker.com'. This is indicative of a link farm or SEO manipulation tactic. While no scripts were explicitly extracted, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests the document's primary purpose is to generate traffic or distribute content via these links. The ML classifier also flagged the PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8313

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/child-protection-domestic-violence-and-parental-substance-misuse-family-experiences.pdf In PDF document text
    • http://www.gorillawalker.com/tina-kane-private-eye-erotic-detective-story.pdfIn PDF document text
    • http://www.gorillawalker.com/nystrom-world-atlas.pdfIn PDF document text
    • http://www.gorillawalker.com/boom-pow-cheerleader-stories-a-mfm-menage-erotica.pdfIn PDF document text
    • http://www.gorillawalker.com/drawing-to-see.pdfIn PDF document text
    • http://www.gorillawalker.com/courage-esther-follow-the-leader-stories.pdfIn PDF document text
    • http://www.gorillawalker.com/fritz-kreisler-eighteenth-variation-from-rhapsodie-on-a-theme-of.pdfIn PDF document text
    • http://www.gorillawalker.com/the-son-of-neptune-heroes-of-olympus-book-2.pdfIn PDF document text
    • http://www.gorillawalker.com/my-big-fat-book-of-totally-gross-stuff-drawn-by.pdfIn PDF document text
    • http://www.gorillawalker.com/the-crimson-chalice.pdfIn PDF document text
    • http://www.gorillawalker.com/howard-b-wigglebottom-and-manners-matters.pdfIn PDF document text
    • http://www.gorillawalker.com/everyday-iran-a-provincial-portrait-of-the-islamic-republic-international.pdfIn PDF document text
    • http://www.gorillawalker.com/quivering-quakes-nd-natural-disasters-chelsea-house.pdfIn PDF document text
    • http://www.gorillawalker.com/beans-from-brazil.pdfIn PDF document text
    • http://www.gorillawalker.com/apple-tree-farm-cut-out-model.pdfIn PDF document text
    • http://www.gorillawalker.com/entrees-a-la-mode-thirteenth-impression.pdfIn PDF document text
    • http://www.gorillawalker.com/best-ever-cook-s-collection-chinese.pdfIn PDF document text
    • http://www.gorillawalker.com/conflict-of-laws-and-the-enforcement-of-the-statutory-liability.pdfIn PDF document text
    • http://www.gorillawalker.com/the-fourfold-gospel-pure-gold-classic-includes-audio-excerpts-on.pdfIn PDF document text
    • http://www.gorillawalker.com/thermae-romae-vol-2.pdfIn PDF document text
    • http://www.gorillawalker.com/pictures-at-an-exhibition-in-a-simple-arrangement-for-piano.pdfIn PDF document text
    • http://www.gorillawalker.com/lawyers-on-trial-understanding-ethical-misconduct.pdfIn PDF document text
    • http://www.gorillawalker.com/yemen.pdfIn PDF document text
    • http://www.gorillawalker.com/state-and-local-politics-government-by-the-people-plus-mypoliscilab.pdfIn PDF document text
    • http://www.gorillawalker.com/perfectly-18-kacey-basement-bondage-and-gag-picture-book-teen.pdfIn PDF document text
    • http://www.gorillawalker.com/bayerisches-gesetz-ber-das-erziehungs-und-unterrichtswesen-bayeug-german-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/how-to-reach-hard-to-teach-pb-children-with-special.pdfIn PDF document text
    • http://www.gorillawalker.com/handbook-of-social-media-and-the-law.pdfIn PDF document text
    • http://www.gorillawalker.com/vintage-jewellery.pdfIn PDF document text
    • http://www.gorillawalker.com/talking-sex.pdfIn PDF document text
    • http://www.gorillawalker.com/on-the-burning-edge-a-fateful-fire-and-the-men.pdfIn PDF document text
    • http://www.gorillawalker.com/closing-the-execution-gap-how-great-leaders-and-their-companies.pdfIn PDF document text
    • http://www.gorillawalker.com/a-night-in-a-moorish-harem-illustrated-classic-victorian-erotica.pdfIn PDF document text
    • http://www.gorillawalker.com/icc-cricket-world-cup-facts-trivia-records-book.pdfIn PDF document text
    • http://www.gorillawalker.com/jay-kordich-s-live-foods-live-bodies.pdfIn PDF document text
    • http://www.gorillawalker.com/message-from-a-blue-jay-love-loss-and-one-writer.pdfIn PDF document text
    • http://www.gorillawalker.com/healing-insomnia-and-tinnitus-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/deutsche-soldaten-uniforms-equipment-and-personal-items-of-the-german.pdfIn PDF document text
    • http://www.gorillawalker.com/anxiety-and-related-disorders-interview-schedule-for-dsm-5-adis.pdfIn PDF document text
    • http://www.gorillawalker.com/inspired-how-to-create-products-customers-love-kindle-edition.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text