Malicious PDF — malware analysis report

Static analysis result for SHA-256 c39dc0314e6b7c50…

MALICIOUS

PDF

31.4 KB Created: 2019-05-24 00:41:47 +03:00 Authoring application: Adobe InDesign CS4 (6.0.4) (via Adobe PDF Library 9.0) First seen: 2020-12-28
MD5: e97bfa06253404d4dde4f2795f0babcd SHA-1: 492f9e5f5105127076eca5e8df21eb42dade7935 SHA-256: c39dc0314e6b7c500132f7d2f58f53a408b02f0429e1b9dec8655d945d43db9f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While no scripts were explicitly extracted, the ML_NYX_PDF_MALICIOUS heuristic and the sheer volume of external links suggest a malicious intent, possibly to manipulate search engine rankings or to serve as a distribution point for further malicious content. The document body appears to be obfuscated or corrupted, preventing a direct analysis of its content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8447

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/the-illustrations-of-my-heart-poems-from-deep-chambers-of.pdf In PDF document text
    • http://www.gorillawalker.com/esl-writing-enhancement-using-moodle-lms.pdfIn PDF document text
    • http://www.gorillawalker.com/chosen-by-the-goddess-hare-to-the-throne-book-2.pdfIn PDF document text
    • http://www.gorillawalker.com/mafalda-4-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/islam-in-transition-muslim-perspectives.pdfIn PDF document text
    • http://www.gorillawalker.com/graphite.pdfIn PDF document text
    • http://www.gorillawalker.com/lebanon-a-target-by-default-the-lebanese-linkages-brief-article.pdfIn PDF document text
    • http://www.gorillawalker.com/el-juego-de-los-cazadores-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/the-grape-cure.pdfIn PDF document text
    • http://www.gorillawalker.com/concerning-the-true-care-of-souls.pdfIn PDF document text
    • http://www.gorillawalker.com/harvesting-rue-the-atlantis-series-book-2.pdfIn PDF document text
    • http://www.gorillawalker.com/how-to-start-a-nursing-home-care-business.pdfIn PDF document text
    • http://www.gorillawalker.com/classic-word-puzzles.pdfIn PDF document text
    • http://www.gorillawalker.com/industrial-marketing-research-techniques-practices.pdfIn PDF document text
    • http://www.gorillawalker.com/warehouse-management-mit-sap-erp.pdfIn PDF document text
    • http://www.gorillawalker.com/all-the-time-in-the-world.pdfIn PDF document text
    • http://www.gorillawalker.com/best-practice-in-labour-and-delivery-cambridge-medicine.pdfIn PDF document text
    • http://www.gorillawalker.com/life-in-the-kingdom-spirit-filled-life-study-guide-series.pdfIn PDF document text
    • http://www.gorillawalker.com/beyond-the-white-house-waging-peace-fighting-disease-building-hope.pdfIn PDF document text
    • http://www.gorillawalker.com/loving-voice-ii-a-caregiver-s-book-of-more-read.pdfIn PDF document text
    • http://www.gorillawalker.com/designing-transportation-fuels-for-a-cleaner-environment-applied-energy-technology.pdfIn PDF document text
    • http://www.gorillawalker.com/canal-zone-pilot-guide-to-the-republic-of-panama-and.pdfIn PDF document text
    • http://www.gorillawalker.com/a-serpent-s-tooth-a-walt-longmire-mystery-book-9.pdfIn PDF document text
    • http://www.gorillawalker.com/reminiscences-of-a-wall-street-trader.pdfIn PDF document text
    • http://www.gorillawalker.com/make-money-selling-services-on-fiverr-making-money-series-book.pdfIn PDF document text
    • http://www.gorillawalker.com/take-out-double-family-your-bridge-to-conventions.pdfIn PDF document text
    • http://www.gorillawalker.com/beyond-the-brain-birth-death-and-transendence-in-psychotherapy-suny.pdfIn PDF document text
    • http://www.gorillawalker.com/the-power-playbook-rules-for-independence-money-and-success.pdfIn PDF document text
    • http://www.gorillawalker.com/highlights-book-of-travel-games.pdfIn PDF document text
    • http://www.gorillawalker.com/riding-buffaloes-and-broncos-rodeo-and-native-traditions-in-the.pdfIn PDF document text
    • http://www.gorillawalker.com/himnos-de-gloria-y-triunfo.pdfIn PDF document text
    • http://www.gorillawalker.com/the-papers-of-robert-morris-1781-150-1784-volume-5.pdfIn PDF document text
    • http://www.gorillawalker.com/secrets-of-chess-training-school-of-future-chess-champions-1.pdfIn PDF document text
    • http://www.gorillawalker.com/extravagaria.pdfIn PDF document text
    • http://www.gorillawalker.com/disney-s-winnie-the-pooh-s-big-book-of-first.pdfIn PDF document text
    • http://www.gorillawalker.com/beware-of-angels-deceptions-in-the-last-days.pdfIn PDF document text
    • http://www.gorillawalker.com/stp-caribbean-mathematics-workbook-1.pdfIn PDF document text
    • http://www.gorillawalker.com/money-and-power-in-anglo-saxon-england-the-southern-english.pdfIn PDF document text
    • http://www.gorillawalker.com/esquire-the-meaning-of-life-wisdom-humor-and-damn-good.pdfIn PDF document text
    • http://www.gorillawalker.com/information-and-communication-technology-for-education-digital.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text