Malicious PDF — malware analysis report

Static analysis result for SHA-256 d60eba5e3f1f9d18…

MALICIOUS

PDF

43.9 KB Created: 2018-12-15 20:57:14 +03:00 Authoring application: PScript5.dll Version 5.2.2 (via iText 2.1.7 by 1T3XT) First seen: 2019-01-12
MD5: fea60413a4af5dade1d6471c9593aa0b SHA-1: 5be2e50a9e85598cb556b962d61fc8bda363aa68 SHA-256: d60eba5e3f1f9d18e262085bcfcbd30f84fdb06e65bf4c04773cdec14a18549d
92 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9007

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/women-and-the-american-labor-movement-from-world-war-i.pdf In PDF document text
    • http://www.gorillawalker.com/exploring-the-history-and-philosophy-of-christian-education-principles-for.pdfIn PDF document text
    • http://www.gorillawalker.com/barron-s-junior-rhyming-dictionary.pdfIn PDF document text
    • http://www.gorillawalker.com/computerized-engine-controls-2002-update.pdfIn PDF document text
    • http://www.gorillawalker.com/argumentum-e-silentio.pdfIn PDF document text
    • http://www.gorillawalker.com/t-cnica-cartom-gica-volume-1-spanish-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/the-courtship-of-miles-standish.pdfIn PDF document text
    • http://www.gorillawalker.com/nextext-historical-readers-student-text-the-immigrants.pdfIn PDF document text
    • http://www.gorillawalker.com/b-52-stratofortress-general-aviation.pdfIn PDF document text
    • http://www.gorillawalker.com/the-shadowing-hunted.pdfIn PDF document text
    • http://www.gorillawalker.com/the-oxford-handbook-of-organization-theory-meta-theoretical-perspectives-oxford.pdfIn PDF document text
    • http://www.gorillawalker.com/ingl-s-en-un-mes-serie-ingles-en-100-dias.pdfIn PDF document text
    • http://www.gorillawalker.com/create-in-me-a-pure-heart-answers-for-struggling-women.pdfIn PDF document text
    • http://www.gorillawalker.com/handbook-of-colposcopy-2ed.pdfIn PDF document text
    • http://www.gorillawalker.com/the-rock-art-of-arizona-art-for-life-s-sake.pdfIn PDF document text
    • http://www.gorillawalker.com/paul-s-necessary-sin-the-experience-of-liberation.pdfIn PDF document text
    • http://www.gorillawalker.com/reich-speaks-of-freud-wilhelm-reich-discusses-his-work-and.pdfIn PDF document text
    • http://www.gorillawalker.com/l-munatius-plancus-serving-and-surviving-in-the-roman-revolution.pdfIn PDF document text
    • http://www.gorillawalker.com/golden-surrender-vikings-trilogy-book-1-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/inflation-unemployment-and-government-deficits-end-them-an-economist-s.pdfIn PDF document text
    • http://www.gorillawalker.com/a-problem-of-evidence-how-the-prosecution-freed-o-j.pdfIn PDF document text
    • http://www.gorillawalker.com/public-hearing-before-assembly-consumer-affairs-committee-assembly-bill-nos.pdfIn PDF document text
    • http://www.gorillawalker.com/medicine-for-mountaineering-other-wilderness-activities.pdfIn PDF document text
    • http://www.gorillawalker.com/radar-meteorology-artech-house-radar-library.pdfIn PDF document text
    • http://www.gorillawalker.com/life-of-the-beloved-spiritual-living-in-a-secular-world.pdfIn PDF document text
    • http://www.gorillawalker.com/prealgebra-dvd-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/barnsley-district-through-time.pdfIn PDF document text
    • http://www.gorillawalker.com/telescopic-hydraulic-gantry-systems.pdfIn PDF document text
    • http://www.gorillawalker.com/the-john-michell-reader-writings-and-rants-of-a-radical.pdfIn PDF document text
    • http://www.gorillawalker.com/nemesis-inception.pdfIn PDF document text
    • http://www.gorillawalker.com/force-reduction-marine-and-army-drawdowns-examined-in-brief-military.pdfIn PDF document text
    • http://www.gorillawalker.com/a-guide-to-garden-visits-with-welcoming-places-to-stay.pdfIn PDF document text
    • http://www.gorillawalker.com/the-billionaire-s-reality-show.pdfIn PDF document text
    • http://www.gorillawalker.com/sonata-op-120-no-1-in-f-minor-alto-saxophone.pdfIn PDF document text
    • http://www.gorillawalker.com/devon-and-cornwall-philip-s-cycle-tours.pdfIn PDF document text
    • http://www.gorillawalker.com/the-lady-and-the-tigers-remembering-the-flying-tigers-of.pdfIn PDF document text
    • http://www.gorillawalker.com/the-mentor-s-field-guide-answers-you-need-to-help.pdfIn PDF document text
    • http://www.gorillawalker.com/california-land-use-and-planning-law-kindle-edition.pdfIn PDF document text
    • http://www.gorillawalker.com/homicide-life-on-the-screen.pdfIn PDF document text
    • http://www.gorillawalker.com/the-history-of-the-first-presbyterian-church-u-s-a.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off00000c22.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0xC22 15939 bytes
SHA-256: 8613da339e58a98f9b69e11a649ae5446a08a74996bc6ffdee0f59c9018e0197