Malicious PDF — malware analysis report

Static analysis result for SHA-256 c72aaccaa09ac492…

MALICIOUS

PDF

44.5 KB Created: 2019-03-30 22:25:23 +03:00 Authoring application: FrameMaker 7.0 (via Acrobat Distiller 5.0.5 (Windows))
MD5: a1aa31ac4bd07c344df4d452b8c3d1cf SHA-1: 72deed4d1522daa05af9252e2fbc01d81e854ff7 SHA-256: c72aaccaa09ac492bcec5c95e293e8ee65719e3ec779f28a12d65b9324c189b7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection tactic. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file. While no scripts were extracted, the sheer volume of links points towards a social engineering attempt to direct users to potentially malicious content hosted on external domains.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8859

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/the-last-month-of-the-year-eight-carols-for-voices.pdf
    • http://www.gorillawalker.com/hylton-nel-a-curious-world.pdf
    • http://www.gorillawalker.com/do-birds-fart-answers-to-50-of-the-coolest-questions.pdf
    • http://www.gorillawalker.com/the-writer-s-handbook-2008.pdf
    • http://www.gorillawalker.com/elememtary-theory-of-metals-international-encyclopaedia-of-physical-chemistry-and.pdf
    • http://www.gorillawalker.com/cellular-and-molecular-neurophysiology-third-edition.pdf
    • http://www.gorillawalker.com/the-dead-sea-scrolls-and-the-roots-of-christianity-and.pdf
    • http://www.gorillawalker.com/oli-ollie-bilingual-board-book-gossie-friends-spanish-and-english.pdf
    • http://www.gorillawalker.com/archaeology-a-brief-introduction-11th-edition.pdf
    • http://www.gorillawalker.com/treating-allergies-with-the-f-x-mayr-cure-mobilizing-the.pdf
    • http://www.gorillawalker.com/die-design-handbook.pdf
    • http://www.gorillawalker.com/etidorhpa-or-the-end-of-the-earth.pdf
    • http://www.gorillawalker.com/tools-teach-an-iconography-of-american-hand-tools-hand-tools.pdf
    • http://www.gorillawalker.com/music-of-the-whole-earth.pdf
    • http://www.gorillawalker.com/das-gew-lbe-des-himmels-3-der-ausgesto-ene-german.pdf
    • http://www.gorillawalker.com/reappraisals-of-the-scientific-revolution.pdf
    • http://www.gorillawalker.com/recipes-for-the-specific-carbohydrate-diet-the-grain-free-lactose.pdf
    • http://www.gorillawalker.com/one-moment-meditation-stillness-for-people-on-the-go.pdf
    • http://www.gorillawalker.com/the-town-called-potential.pdf
    • http://www.gorillawalker.com/graded-tongue-training-grade-1-beginners-and-teachers-for-cornet.pdf
    • http://www.gorillawalker.com/tropical-mycology-cabi.pdf
    • http://www.gorillawalker.com/the-wednesday-surprise.pdf
    • http://www.gorillawalker.com/a-practical-guide-to-inspecting-interiors.pdf
    • http://www.gorillawalker.com/photographing-minerals-fossils-and-lapidary-materials.pdf
    • http://www.gorillawalker.com/my-travel-journal-color-suitcases-travel-planner-journal-6-x.pdf
    • http://www.gorillawalker.com/washing-of-the-spears-a-history-of-the-rise-of.pdf
    • http://www.gorillawalker.com/independence-lost-lives-on-the-edge-of-the-american-revolution.pdf
    • http://www.gorillawalker.com/applying-international-accounting-standards-1st-first-edition.pdf
    • http://www.gorillawalker.com/the-ramage-touch.pdf
    • http://www.gorillawalker.com/the-nobleman-and-the-spy.pdf
    • http://www.gorillawalker.com/aristophanes-clouds-acharnians-lysistrata-a-companion-to-the-penguin-translation.pdf
    • http://www.gorillawalker.com/business-law-today-8th-egith-edition-text-only.pdf
    • http://www.gorillawalker.com/nutribullet-recipe-book-the-nutribullet-natural-healing-foods-book-nutribullet.pdf
    • http://www.gorillawalker.com/wringer-turtleback-school-library-binding-edition.pdf
    • http://www.gorillawalker.com/agnes-macphail-quest-library-xyz-publishing.pdf
    • http://www.gorillawalker.com/special-edition-kindle-edition.pdf
    • http://www.gorillawalker.com/orchestral-music-a-source-book.pdf
    • http://www.gorillawalker.com/smoke-a-cigar-a-gentleman-s-quick-and-easy-guide.pdf
    • http://www.gorillawalker.com/ethnic-groups-in-the-republic-of-turkey-unver-nderter-nachdruck.pdf
    • http://www.gorillawalker.com/isadora-duncan-dance.pdf
    • http://www.gorillawalker.com/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/