Malicious PDF — malware analysis report

Static analysis result for SHA-256 5436768626e70270…

MALICIOUS

PDF

46.6 KB Created: 2018-12-15 08:11:13 +03:00 Authoring application: AdobePS5.dll Version 5.0.1 (via Acrobat Distiller 4.0 for Windows)
MD5: 0a099c11fba1846d308a9f1c3e48a3b6 SHA-1: 2195f99214d8eafcb68c4dd40dd18451eb1f2501 SHA-256: 5436768626e70270e93033249de13f75fbdb6bafce43e732ea000ad6c7bb9af3
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The file was detected as malicious by ClamAV with the signature Pdf.Dropper.Agent-7147267-0 and a machine learning classifier. It contains multiple external URIs pointing to various PDF files on the gorillawalker.com domain. These URLs are likely used to host or distribute further malicious content, acting as a dropper or redirector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8013

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7147267-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7147267-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/rafe-a-christian-western-kindle-edition.pdf
    • http://www.gorillawalker.com/invincible-the-chronicles-of-nick.pdf
    • http://www.gorillawalker.com/israel-an-echo-of-eternity.pdf
    • http://www.gorillawalker.com/angry-birds-go-ultimate-edition-guide-kindle-edition.pdf
    • http://www.gorillawalker.com/samantha-the-sequel.pdf
    • http://www.gorillawalker.com/sherman-s-horsemen-union-cavalry-operations-in-the-atlanta-campaign.pdf
    • http://www.gorillawalker.com/seals-the-us-navy-s-elite-fighting-force-general-military.pdf
    • http://www.gorillawalker.com/music-from-the-motion-picture-brokeback-mountain-piano-vocal-guitar.pdf
    • http://www.gorillawalker.com/los-misterios-del-fuego-kundalini-yoga-spanish-edition.pdf
    • http://www.gorillawalker.com/frontiers-and-prospects-of-contemporary-applied-mathematics-series-in-contemporary.pdf
    • http://www.gorillawalker.com/the-little-giant-encyclopedia-of-card-games-gift-set.pdf
    • http://www.gorillawalker.com/fisheries-co-management-in-bangladesh-a-new-approach-for-fisheries.pdf
    • http://www.gorillawalker.com/sex-tips-for-girls.pdf
    • http://www.gorillawalker.com/the-airbnb-entrepreneur-how-to-earn-big-profits-even-if.pdf
    • http://www.gorillawalker.com/mailed-fist-6th-armour-division-at-war-1940-1945.pdf
    • http://www.gorillawalker.com/the-business-of-america-is-lobbying-how-corporations-became-politicized.pdf
    • http://www.gorillawalker.com/the-empty-tomb-jesus-beyond-the-grave.pdf
    • http://www.gorillawalker.com/communicating-to-advance-the-public-s-health-workshop-summary.pdf
    • http://www.gorillawalker.com/brooks-cole-empowerment-series-becoming-an-effective-policy-advocate.pdf
    • http://www.gorillawalker.com/the-international-school-of-sugarcraft-sugar-flowers.pdf
    • http://www.gorillawalker.com/split-infinity-apprentice-adept-series-book-1-unabridged-audible-audio.pdf
    • http://www.gorillawalker.com/jamestown-s-american-portraits-the-worst-of-times.pdf
    • http://www.gorillawalker.com/prancercise-the-art-of-physical-and-spiritual-excellence.pdf
    • http://www.gorillawalker.com/diseases-of-the-ear.pdf
    • http://www.gorillawalker.com/winnie-the-pooh-123-book.pdf
    • http://www.gorillawalker.com/joy-in-my-soul.pdf
    • http://www.gorillawalker.com/surviving-ireland.pdf
    • http://www.gorillawalker.com/river-primeval.pdf
    • http://www.gorillawalker.com/quirky-yes-hopeless-no-practical-tips-to-help-your-child.pdf
    • http://www.gorillawalker.com/silk-designs-of-the-eighteenth-century-from-the-victoria-and.pdf
    • http://www.gorillawalker.com/johnny-cash-for-ukulele.pdf
    • http://www.gorillawalker.com/coaching-for-innovation-tools-and-techniques-for-encouraging-new-ideas.pdf
    • http://www.gorillawalker.com/the-mask-a-periodical-performance-by-edward-gordon-craig-contemporary.pdf
    • http://www.gorillawalker.com/casablanca-chandigarh-a-report-on-modernization.pdf
    • http://www.gorillawalker.com/on-computing-the-fourth-great-scientific-domain.pdf
    • http://www.gorillawalker.com/the-late-henry-moss-eyes-for-consuela-when-the-world.pdf
    • http://www.gorillawalker.com/understanding-military-sexual-trauma-a-guide-for-those-who-work.pdf
    • http://www.gorillawalker.com/healthy-flier-how-to-protect-yourself-from-the-hidden-hazards.pdf
    • http://www.gorillawalker.com/how-my-mother-accidentally-tossed-out-my-entire-baseball-card.pdf
    • http://www.gorillawalker.com/freaks-talk-back-tabloid-talk-shows-and-sexual-nonconformity.pdf
    • http://www.gorillawalker.com/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/