Malicious PDF — malware analysis report

Static analysis result for SHA-256 cfacac91ac0ce775…

MALICIOUS

PDF

45.5 KB Created: 2018-12-15 21:25:43 +03:00 Authoring application: - (via PDFlib Personalization Server 5.0.1 (COM/Win32) unlicensed) First seen: 2019-02-10
MD5: 78f356f72cd2aa412a10f77703b9ee7e SHA-1: fd4b1496ed92a94e2d94c9ad4038ce38702b3b80 SHA-256: cfacac91ac0ce775b37bf07a525dc96e34b9df2c104b5e9067dae319c6e22e6a
92 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.8173

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/tainted-wounds-tainted-wounds-master-manipulator-kindle-edition.pdf In PDF document text
    • http://www.gorillawalker.com/les-loustics-2-a1-cahier-d-activites-cd-audio-french.pdfIn PDF document text
    • http://www.gorillawalker.com/legal-services-bill-second-marshalled-list-of-amendments-to-be.pdfIn PDF document text
    • http://www.gorillawalker.com/boz-good-morning-boz-boz-series.pdfIn PDF document text
    • http://www.gorillawalker.com/jonny-lang-lie-to-me-authentic-guitar-tab-with-qwik.pdfIn PDF document text
    • http://www.gorillawalker.com/paul-mckenna-s-sports-hypnosis-superb-squash.pdfIn PDF document text
    • http://www.gorillawalker.com/narrative-of-a-visit-to-brazil-chile-peru-and-the.pdfIn PDF document text
    • http://www.gorillawalker.com/british-biotech-minutes-of-evidence-tuesday-28-july-1998-house.pdfIn PDF document text
    • http://www.gorillawalker.com/i-due-foscari-vocal-score-paper-italian.pdfIn PDF document text
    • http://www.gorillawalker.com/the-shirtmaking-workbook-pattern-design-and-construction-resources-for-shirtmaking.pdfIn PDF document text
    • http://www.gorillawalker.com/noah-s-ark-tummy-time-soft-book.pdfIn PDF document text
    • http://www.gorillawalker.com/earthquake-emergency.pdfIn PDF document text
    • http://www.gorillawalker.com/british-army-against-napoleon-the-facts-lists-and-trivia-1805.pdfIn PDF document text
    • http://www.gorillawalker.com/photoshop-artistry-for-photographers-using-photoshop-cs2-and-beyond.pdfIn PDF document text
    • http://www.gorillawalker.com/deathwatch.pdfIn PDF document text
    • http://www.gorillawalker.com/dead-serious-hard-rock-roots-volume-6.pdfIn PDF document text
    • http://www.gorillawalker.com/to-prevail-an-american-strategy-for-the-campaign-against-terrorism.pdfIn PDF document text
    • http://www.gorillawalker.com/brain-quest-card-game-grades-5-and-6-stuff-you.pdfIn PDF document text
    • http://www.gorillawalker.com/tibetan-terrier-calendar-breed-specific-tibetan-terrier-calendar-2016-wall.pdfIn PDF document text
    • http://www.gorillawalker.com/knitted-knotted-twisted-and-twined-the-jewelry-of-mary-lee.pdfIn PDF document text
    • http://www.gorillawalker.com/surface-acoustic-wave-devices-for-mobile-and-wireless-communications.pdfIn PDF document text
    • http://www.gorillawalker.com/targeting-a-great-career-the-five-o-clock-club.pdfIn PDF document text
    • http://www.gorillawalker.com/harcourt-school-publishers-villa-cuentos-student-edition-giros-y-piruetas.pdfIn PDF document text
    • http://www.gorillawalker.com/harpercollins-new-world-atlas-hardcover.pdfIn PDF document text
    • http://www.gorillawalker.com/after-hours-with-her-ex-harlequin-desire.pdfIn PDF document text
    • http://www.gorillawalker.com/artificial-cognitive-systems-a-primer-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/handbook-of-continued-fractions-for-special-functions.pdfIn PDF document text
    • http://www.gorillawalker.com/interior-design-a-practical-guide-abrams-studio.pdfIn PDF document text
    • http://www.gorillawalker.com/make-up-your-mind-a-decision-making-guide-to-thinking.pdfIn PDF document text
    • http://www.gorillawalker.com/delivery-cupid.pdfIn PDF document text
    • http://www.gorillawalker.com/i-married-mr-america.pdfIn PDF document text
    • http://www.gorillawalker.com/det-norske-folks-historie-deel-1-bd-1-afsnit-bebyggelsen.pdfIn PDF document text
    • http://www.gorillawalker.com/pale-gray-for-guilt-travis-mcgee-series.pdfIn PDF document text
    • http://www.gorillawalker.com/introducing-liberative-theologies-introducing-series.pdfIn PDF document text
    • http://www.gorillawalker.com/after-shadow.pdfIn PDF document text
    • http://www.gorillawalker.com/birds-peace-wealth-aristophanes-critique-of-the-gods.pdfIn PDF document text
    • http://www.gorillawalker.com/aat-nvq-cash-transactions-unit-1-paperback.pdfIn PDF document text
    • http://www.gorillawalker.com/smoothies-for-weight-loss-50-most-most-watering-healthy-recipes.pdfIn PDF document text
    • http://www.gorillawalker.com/99-maths-puzzles-usborne-puzzle-books.pdfIn PDF document text
    • http://www.gorillawalker.com/circle-of-five-the-pha-yul-trilogy-book-1-kindle.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off000018ff.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x18FF 28622 bytes
SHA-256: 4194ca64526d367ed8bc9bbdf0fcb9a5ea1f01c5fff4a01faeb30e5a9f69e153