Malicious PDF — malware analysis report

Static analysis result for SHA-256 cecc50c60c38c580…

MALICIOUS

PDF

44.6 KB Created: 2019-02-13 20:08:06 +03:00 Authoring application: Writer (via OpenOffice.org 2.0.3)
MD5: 8647b1addef442022981fa2c0d83634c SHA-1: 3f6c37430024f81f4e2d53bd6e6576e3c8c6508c SHA-256: cecc50c60c38c580e75ecc2cf623f165e12646bf7734dc0f1f0167fd366a51f9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, identified by the 'PDF_SEO_LINK_FARM' heuristic. These links point to various PDF documents hosted on 'gorillawalker.com'. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be a link farm designed to direct users to potentially malicious or unwanted content hosted externally.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8452

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/academic-encounters-level-3-teacher-s-manual-reading-and-writing.pdf
    • http://www.gorillawalker.com/kinetic-systems-mathematical-description-of-chemical-kinetics-in-solution.pdf
    • http://www.gorillawalker.com/sociodynamics-a-systematic-approach-to-mathematical-modelling-in-the-social.pdf
    • http://www.gorillawalker.com/quien-mato-el-cambio-historia-de-un-asesinato-corporativo-who.pdf
    • http://www.gorillawalker.com/the-storm-a-profitable-position-and-other-plays-russian-edition.pdf
    • http://www.gorillawalker.com/easy-gospel-mandolin-solos-vol-2-book-cd.pdf
    • http://www.gorillawalker.com/fresh-and-simple-quick-toss-salad-meals.pdf
    • http://www.gorillawalker.com/backpacking-the-complete-backpacking-guide-to-getting-you-started-on.pdf
    • http://www.gorillawalker.com/myth-and-scripture-contemporary-perspectives-on-religion-language-and-imagination.pdf
    • http://www.gorillawalker.com/guide-to-andalucia.pdf
    • http://www.gorillawalker.com/principled-judicial-restraint-a-case-against-activism.pdf
    • http://www.gorillawalker.com/belligerent-muse-five-northern-writers-and-how-they-shaped-our.pdf
    • http://www.gorillawalker.com/shaken-faith-syndrome-strengthening-one-s-testimony-in-the-face.pdf
    • http://www.gorillawalker.com/soa-in-practice-the-art-of-distributed-system-design-theory.pdf
    • http://www.gorillawalker.com/plowing-in-hope-towards-a-biblical-theology-of-culture.pdf
    • http://www.gorillawalker.com/breath-life-in-the-rhythm-of-an-iron-lung.pdf
    • http://www.gorillawalker.com/john-wesley-on-the-sacraments-a-theological-study.pdf
    • http://www.gorillawalker.com/the-complete-guide-to-fashion-illustration.pdf
    • http://www.gorillawalker.com/thermodynamics-and-the-destruction-of-resources.pdf
    • http://www.gorillawalker.com/ibsen-four-major-plays-vol-ii.pdf
    • http://www.gorillawalker.com/official-soviet-mosin-nagant-rifle-manual-operating-instructions-for-the.pdf
    • http://www.gorillawalker.com/advances-in-solid-state-physics-45.pdf
    • http://www.gorillawalker.com/lost-breweries-of-toronto.pdf
    • http://www.gorillawalker.com/solar-power-energy-today.pdf
    • http://www.gorillawalker.com/product-and-process-design-principles-synthesis-analysis-and-design.pdf
    • http://www.gorillawalker.com/international-comparative-employment-relations.pdf
    • http://www.gorillawalker.com/the-pebble-first-guide-to-rocks-and-minerals-pebble-first.pdf
    • http://www.gorillawalker.com/american-journal-of-dental-science-volume-28.pdf
    • http://www.gorillawalker.com/developing-agility-and-quickness-sport-performance.pdf
    • http://www.gorillawalker.com/my-daily-walk-discover-the-life-of-jesus.pdf
    • http://www.gorillawalker.com/rand-mcnally-1st-edition-des-moines-street-guide.pdf
    • http://www.gorillawalker.com/picturing-poverty-print-culture-and-fsa-photographs.pdf
    • http://www.gorillawalker.com/de-profundis-clasicos-de-la-literatura-series-spanish-edition.pdf
    • http://www.gorillawalker.com/sophie-la-girafe-on-the-move.pdf
    • http://www.gorillawalker.com/barron-s-how-to-prepare-for-the-ged-canadian-edition.pdf
    • http://www.gorillawalker.com/mcgraw-hill-education-gmat-2016-strategies-10-practice-tests-11.pdf
    • http://www.gorillawalker.com/the-english-execution-narrative-1200-1700-the-body-gender-and.pdf
    • http://www.gorillawalker.com/points-de-depart.pdf
    • http://www.gorillawalker.com/dead-light.pdf
    • http://www.gorillawalker.com/ntc-s-english-idioms-dictionary.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/