Malicious PDF — malware analysis report

Static analysis result for SHA-256 dc2be71661eaa38e…

MALICIOUS

PDF

44.4 KB Created: 2019-03-17 05:27:07 +03:00 Authoring application: calibre 0.9.13 [http://calibre-ebook.com]
MD5: c8d82c7b8db6733129cd8c2f763d9fea SHA-1: 4ce0cde89a853e85e414a6f89939bcb1589d3856 SHA-256: dc2be71661eaa38e856fa794790ef0d8808b648193c5a6d2cbff533480f730dc
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files hosted on the 'gorillawalker.com' domain. This is indicative of a link farm or SEO manipulation tactic. The ML classifier also flagged this PDF as malicious. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8439

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/ancient-athens-rebuilt-and-relived-grade-iv-columbia-university-teachers.pdf
    • http://www.gorillawalker.com/beneath-the-crashing-waves-adronis-novella-2-volume-2.pdf
    • http://www.gorillawalker.com/faust-parts-1-and-2-oxford-library-of-the-world.pdf
    • http://www.gorillawalker.com/classics-in-italian-literature.pdf
    • http://www.gorillawalker.com/faithful-over-a-few-things-study-guide.pdf
    • http://www.gorillawalker.com/african-american-cookbook-traditional-and-other-favorite-recipes.pdf
    • http://www.gorillawalker.com/freedom-s-challenge-freedom-series-book-3.pdf
    • http://www.gorillawalker.com/spirit-of-the-rebellion.pdf
    • http://www.gorillawalker.com/live-the-adventure.pdf
    • http://www.gorillawalker.com/takezo-learns-to-swim.pdf
    • http://www.gorillawalker.com/east-leeds-1908-yorkshire-sheet-218-03-old-o-s.pdf
    • http://www.gorillawalker.com/rand-mcnally-titusville-cocoa-melbourne-florida.pdf
    • http://www.gorillawalker.com/painting-in-latin-america-1550-150-1820-from-conquest-to.pdf
    • http://www.gorillawalker.com/prickly-plants-the-strangest-plants-on-earth.pdf
    • http://www.gorillawalker.com/home-barista-the-art-of-making-professional-quality-espresso-drinks.pdf
    • http://www.gorillawalker.com/mercedes-benz-japanese-edition.pdf
    • http://www.gorillawalker.com/tinkle-tinkle-little-tot-songs-and-rhymes-for-toilet-training.pdf
    • http://www.gorillawalker.com/the-beautiful-unseen-a-memoir.pdf
    • http://www.gorillawalker.com/oriental-carpets-from-the-tents-cottages-and-workshops-of-asia.pdf
    • http://www.gorillawalker.com/weird-animals-sticker-sheets-10-sheets-weird-animals-vbs.pdf
    • http://www.gorillawalker.com/the-new-victorians-poverty-politics-and-propaganda-in-two-gilded.pdf
    • http://www.gorillawalker.com/sheaves-in-topology-universitext.pdf
    • http://www.gorillawalker.com/35-classroom-management-strategies-promoting-learning-and-building-community.pdf
    • http://www.gorillawalker.com/manual-para-la-evaluaci-n-cl-nica-de-los-trastornos.pdf
    • http://www.gorillawalker.com/our-indigenous-ancestors-a-cultural-history-of-museums-science-and.pdf
    • http://www.gorillawalker.com/way-back-in-the-korn-fields.pdf
    • http://www.gorillawalker.com/the-social-norms-approach-to-preventing-school-and-college-age.pdf
    • http://www.gorillawalker.com/encapsulation-technologies-for-electronic-applications.pdf
    • http://www.gorillawalker.com/audel-small-gasoline-engines-service-and-repair.pdf
    • http://www.gorillawalker.com/basic-dysrhythmias-interpretation-management.pdf
    • http://www.gorillawalker.com/asuncion.pdf
    • http://www.gorillawalker.com/history-of-southern-africa.pdf
    • http://www.gorillawalker.com/lonely-planet-indonesia-s-eastern-islands.pdf
    • http://www.gorillawalker.com/planning-algorithms.pdf
    • http://www.gorillawalker.com/crossing-the-chasm-marketing-and-selling-technology-projects-to-mainstream.pdf
    • http://www.gorillawalker.com/blissful-body-painless-path-learn-how-to-recognize-the-causes.pdf
    • http://www.gorillawalker.com/knitting-with-dog-hair-better-a-sweater-from-a-dog.pdf
    • http://www.gorillawalker.com/ecumenism-in-praxis-a-historical-critique-of-the-malankara-mar.pdf
    • http://www.gorillawalker.com/granville-holiday.pdf
    • http://www.gorillawalker.com/internet-of-things-with-arduino-blueprints.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://calibre-ebook.com
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/