Malicious PDF — malware analysis report

Static analysis result for SHA-256 d099b8d11971f5dc…

MALICIOUS

PDF

39.1 KB Created: 2019-03-18 08:34:24 +03:00 Authoring application: Adobe Illustrator CS3 (via Adobe PDF library 8.00)
MD5: 0f06d1d3cf95ba5a73f773c44491ed7d SHA-1: df7b7a23a553161c4c639607c15408e8dd5d13e1 SHA-256: d099b8d11971f5dc6d15c22f771daaf8303d7e1b2983b217aae87dffd9783257
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF documents on the gorillawalker.com domain. This suggests a link farm or content distribution strategy. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of its specific intent beyond link distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8505

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/pct-technician-s-handbook-a-guide-to-pest-identification-management.pdf
    • http://www.gorillawalker.com/popular-potato-recipes.pdf
    • http://www.gorillawalker.com/marmosets-and-tamarins-pocket-identification-guide-conservation-international-pocket-guide.pdf
    • http://www.gorillawalker.com/guide-to-the-heartman-manuscripts-on-slavery.pdf
    • http://www.gorillawalker.com/a-history-of-the-oratorio-vol-4-the-oratorio-in.pdf
    • http://www.gorillawalker.com/tuscany-tour-atlas.pdf
    • http://www.gorillawalker.com/thermal-power-plant-simulation-and-control-power-and-energy.pdf
    • http://www.gorillawalker.com/stephen-biesty-s-cross-sections-castle.pdf
    • http://www.gorillawalker.com/more.pdf
    • http://www.gorillawalker.com/om-5-with-coursemate-printed-access-card-new-engaging-titles.pdf
    • http://www.gorillawalker.com/sonochemistry.pdf
    • http://www.gorillawalker.com/circular-v-165.pdf
    • http://www.gorillawalker.com/acts-the-church-ignited-part-1-wisdom-of-the-word.pdf
    • http://www.gorillawalker.com/two-little-trains.pdf
    • http://www.gorillawalker.com/good-food-from-ireland.pdf
    • http://www.gorillawalker.com/sietera-ratones-ciegos-seven-blind-mice-spanish-edition.pdf
    • http://www.gorillawalker.com/studies-in-classical-hebrew-studia-judaica.pdf
    • http://www.gorillawalker.com/citytech-the-battletech-game-of-urban-combat-box-set.pdf
    • http://www.gorillawalker.com/counterclockwise-my-year-of-hypnosis-hormones-dark-chocolate-and-other.pdf
    • http://www.gorillawalker.com/ein-herz-und-ein-sinn-op-323-harp-part-qty.pdf
    • http://www.gorillawalker.com/airport-planning-and-management-6-e.pdf
    • http://www.gorillawalker.com/freedom-from-chronic-pain-the-breakthrough-program-that-brings-relief.pdf
    • http://www.gorillawalker.com/nolan-s-labor-and-employment-arbitration-in-a-nutshell-2d.pdf
    • http://www.gorillawalker.com/hospital-and-health-care-administration.pdf
    • http://www.gorillawalker.com/bloodborne-vampiress-thrillogy-book-1-kindle-edition.pdf
    • http://www.gorillawalker.com/russian-cooking-golden-cooking-card-bk.pdf
    • http://www.gorillawalker.com/advances-in-parasitology-volume-9-apl-volume-9.pdf
    • http://www.gorillawalker.com/the-night-in-question.pdf
    • http://www.gorillawalker.com/hydrometry-ihe-delft-lecture-note-series-unesco-ihe-lecture-notes.pdf
    • http://www.gorillawalker.com/society-the-basics-11th-edition.pdf
    • http://www.gorillawalker.com/dvorak-antonin-piano-quartet-no-1-in-d-major-op.pdf
    • http://www.gorillawalker.com/the-houstorian-dictionary.pdf
    • http://www.gorillawalker.com/an-introduction-to-historical-geology-with-special-reference-to-north.pdf
    • http://www.gorillawalker.com/love-under-attack-frcc-book-1.pdf
    • http://www.gorillawalker.com/hawaiian-beach-house-fuckers.pdf
    • http://www.gorillawalker.com/ice-water-in-hell-the-city.pdf
    • http://www.gorillawalker.com/women-accounting-and-narrative-keeping-books-in-eighteenth-century-england.pdf
    • http://www.gorillawalker.com/death-comes-for-the-archbishop-easyread-edition.pdf
    • http://www.gorillawalker.com/concerto-for-e-flat-alto-saxophone-and-chamber-orchestra-or.pdf
    • http://www.gorillawalker.com/gaylord-phoenix.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/