Malicious PDF — malware analysis report

Static analysis result for SHA-256 ebf2018b4f447a57…

MALICIOUS

PDF

43.5 KB Created: 2018-11-14 11:31:03 +03:00 Authoring application: doPDF Ver 7.1 Build 349 (Windows XP Professional Edition (SP 3) - Version: 5.1.2600 (x86))
MD5: e9fb7f280912304f70891afafd0204d2 SHA-1: 171e9ef6f999d8ef830c08628f102e1e9d59b41e SHA-256: ebf2018b4f447a57fe5321de36d0f076acf996cc9ffbc4034d7ed248ed857f4c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content indirectly. The ML classifier also flagged this PDF as malicious. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9171

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/dangerous-lies.pdf
    • http://www.gorillawalker.com/no-worries-the-indispensable-guide-to-ghana-accra-new-5th.pdf
    • http://www.gorillawalker.com/tdx4.pdf
    • http://www.gorillawalker.com/the-art-of-ballet.pdf
    • http://www.gorillawalker.com/i-survived-4-i-survived-the-bombing-of-pearl-harbor.pdf
    • http://www.gorillawalker.com/looking-jewish-visual-culture-and-modern-diaspora.pdf
    • http://www.gorillawalker.com/intellectual-property-patents-trademarks-and-copyright-nutshell-series.pdf
    • http://www.gorillawalker.com/judgment-calls-twelve-stories-of-big-decisions-and-the-teams.pdf
    • http://www.gorillawalker.com/radclyffe-hall-a-case-of-obscenity.pdf
    • http://www.gorillawalker.com/the-right-hon-r-j-seddon-s-the-premier-of.pdf
    • http://www.gorillawalker.com/someday-this-pain-will-be-useful-to-you-a-novel.pdf
    • http://www.gorillawalker.com/oxford-little-english-chinese-dictionary-new-edition.pdf
    • http://www.gorillawalker.com/complement-methods-and-protocols-methods-in-molecular-biology.pdf
    • http://www.gorillawalker.com/hero-strong-and-other-stories-tales-of-girlhood-ambition-female.pdf
    • http://www.gorillawalker.com/the-complete-pci-express-reference-design-implications-for-hardware-and.pdf
    • http://www.gorillawalker.com/from-evolution-to-eden-making-sense-of-early-genesis.pdf
    • http://www.gorillawalker.com/fundamentals-of-forestry-economics.pdf
    • http://www.gorillawalker.com/masquerade-swept-away.pdf
    • http://www.gorillawalker.com/microsoft-windows-xp-unleashed.pdf
    • http://www.gorillawalker.com/loyalty-cards-in-the-apparel-industry-in-germany-and-spain.pdf
    • http://www.gorillawalker.com/good-mood-bad-mood-help-and-hope-for-depression-and.pdf
    • http://www.gorillawalker.com/minecraft-combat-handbook.pdf
    • http://www.gorillawalker.com/rand-mcnally-streetfinder-dallas-vicinity.pdf
    • http://www.gorillawalker.com/act-strategy-winning-multiple-choice-strategies-for-the-act-exam.pdf
    • http://www.gorillawalker.com/acoustics-and-noise-control-handbook-for-architects-and-builders.pdf
    • http://www.gorillawalker.com/zagat-to-go-pack-2009-new-york-city-restaurants.pdf
    • http://www.gorillawalker.com/rome-ii-regulation-pocket-commentary-pocket-commentaries-on-european-regulations.pdf
    • http://www.gorillawalker.com/world-war-i-everyday-life-everyday-life-good-year-books.pdf
    • http://www.gorillawalker.com/china-5-000-years-innovation-and-transformation-in-the-arts.pdf
    • http://www.gorillawalker.com/algebraic-geometry-in-coding-theory-and-cryptography.pdf
    • http://www.gorillawalker.com/frames-of-mind-the-theory-of-multiple-intelligences.pdf
    • http://www.gorillawalker.com/yu-gi-oh-duelists-of-the-roses-prima-s-official.pdf
    • http://www.gorillawalker.com/the-pregnancy-prescription-the-success-oriented-approach-to-overcoming-infertility.pdf
    • http://www.gorillawalker.com/play-doh-rainbow-butterflies-play-doh-first-concepts.pdf
    • http://www.gorillawalker.com/enigmas-y-juegos-de-ingenio-para-romperte-la-cabeza-the.pdf
    • http://www.gorillawalker.com/the-writing-on-the-wall-hearts-of-the-children-1.pdf
    • http://www.gorillawalker.com/introduction-to-matrix-methods-in-optics-dover-books-on-physics.pdf
    • http://www.gorillawalker.com/you-say-more-than-you-think-a-7-day-plan.pdf
    • http://www.gorillawalker.com/wings-spot-the-difference.pdf
    • http://www.gorillawalker.com/the-economic-impact-of-downhill-skiing-at-alberta-s-rocky.pdf
    • http://www.gorillawalker.com/judgment-call
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/