Malicious PDF — malware analysis report

Static analysis result for SHA-256 315b3bb1d3647b5d…

MALICIOUS

PDF

43.8 KB Created: 2018-11-15 18:33:57 +03:00 Authoring application: Pages (via Mac OS X 10.11.6 Quartz PDFContext)
MD5: 91a7d8e58eea35ec012850b20132618e SHA-1: d09e159eeed7f90e9734d08506c10b7c6d272587 SHA-256: 315b3bb1d3647b5da5953c9b3f2a6e70ab7f9c90438e2b7399b63e0ca8649cd4
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The ClamAV heuristic identified this PDF as a dropper, and it contains multiple embedded URLs pointing to other PDF files. The presence of these external links suggests an attempt to lure the user into downloading further malicious content. No scripts were extracted from this sample.

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7246120-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7246120-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/terminal-ellie-jordan-ghost-trapper-book-4-kindle-edition.pdf
    • http://www.gorillawalker.com/first-book-of-practical-studies-for-tuba.pdf
    • http://www.gorillawalker.com/three-shakespeare-songs-vocal-score.pdf
    • http://www.gorillawalker.com/isaak-ignaz-moscheles-the-life-of-the-composer-and-his.pdf
    • http://www.gorillawalker.com/hacking-exposed-7-network-security-secrets-amp-solutions-hacking-exposed.pdf
    • http://www.gorillawalker.com/application-of-computers-in-technology.pdf
    • http://www.gorillawalker.com/polymer-syntheses-organic-chemistry-monographs.pdf
    • http://www.gorillawalker.com/character-education-everyone-is-special-and-unique-learning-about-acceptance.pdf
    • http://www.gorillawalker.com/doll-celebrations-special-reasons-for-your-doll-to-party-play.pdf
    • http://www.gorillawalker.com/the-universal-dictionary-of-biography-and-mythology-vol-iv-in.pdf
    • http://www.gorillawalker.com/what-is-lean-six-sigma.pdf
    • http://www.gorillawalker.com/when-jesus-wept-the-jerusalem-chronicles.pdf
    • http://www.gorillawalker.com/contemporary-aspects-of-complex-analysis-differential-geometry-and-mathematical-physics.pdf
    • http://www.gorillawalker.com/how-to-become-unstoppable-seven-things-every-coach-must-know.pdf
    • http://www.gorillawalker.com/a-transgender-s-faith.pdf
    • http://www.gorillawalker.com/hymns-old-and-new.pdf
    • http://www.gorillawalker.com/multiphoton-microscopy-in-the-biomedical-sciences-iii-proceedings-of-spie.pdf
    • http://www.gorillawalker.com/dr-jekyll-and-mr-hyde-york-notes-for-gcse-2015.pdf
    • http://www.gorillawalker.com/growing-crystals-true-books-earth-science.pdf
    • http://www.gorillawalker.com/india-the-cookbook-hardcover.pdf
    • http://www.gorillawalker.com/cave-city-and-eagle-s-nest-an-interpretive-journey-through.pdf
    • http://www.gorillawalker.com/henri-s-scissors.pdf
    • http://www.gorillawalker.com/wat-wil-jy-weet-gr-10-n-boek-vir-suid.pdf
    • http://www.gorillawalker.com/the-marine-chronometer-its-history-and-development.pdf
    • http://www.gorillawalker.com/fair-gentlemen-of-belken-county-claros-varones-de-belken-klail.pdf
    • http://www.gorillawalker.com/the-making-of-america-the-substance-and-meaning-of-the.pdf
    • http://www.gorillawalker.com/gentlemen-bastards-on-the-ground-in-afghanistan-with-america-s.pdf
    • http://www.gorillawalker.com/luna-de-senegal-senegal-moon-sopa-de-libros-book-soup.pdf
    • http://www.gorillawalker.com/in-our-defense-the-bill-of-rights-in-action.pdf
    • http://www.gorillawalker.com/dogs-their-fossil-relatives-and-evolutionary-history.pdf
    • http://www.gorillawalker.com/milan-pocket-map-guide-dk-eyewitness-pocket-map-and-guide.pdf
    • http://www.gorillawalker.com/saint-genet-actor-and-martyr.pdf
    • http://www.gorillawalker.com/architecture-and-panelling-the-james-a-de-rothschild-bequest-at.pdf
    • http://www.gorillawalker.com/gaumenkino-rezepte-f.pdf
    • http://www.gorillawalker.com/oprah-winfrey-success-with-an-open-heart-gateway-biographies.pdf
    • http://www.gorillawalker.com/under-the-sun-a-sonoran-desert-odyssey.pdf
    • http://www.gorillawalker.com/in-the-bathhouse-poem-an-article-from-the-antioch-review.pdf
    • http://www.gorillawalker.com/oil-pulling-for-beginners-oil-pulling-therapy-the-all-natural.pdf
    • http://www.gorillawalker.com/franciscan-dining-services-a-comprehensive-guide-with-values.pdf
    • http://www.gorillawalker.com/ese-dulce-mal-compactos-spanish-edition.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/