Pdf.Dropper.Agent — PDF malware analysis

Static analysis result for SHA-256 9612b63acd85a501…

MALICIOUS

PDF

44.6 KB Created: 2018-11-14 08:16:36 +03:00 Authoring application: - (via Acrobat Distiller 15.0 (Windows))
MD5: 80c40f5a10759f3d4c49905db730e92c SHA-1: d1ad056ec50b057522808c1660dcac94024fd8cb SHA-256: 9612b63acd85a501ce8649ac5c3d1428ef6e6441b332173ced81bedc36fae871
62 Risk Score

Malware Insights

Pdf.Dropper.Agent · confidence 95%

MITRE ATT&CK
T1204 Malicious Link T1059 Command and Scripting Interpreter

The file was detected as Pdf.Dropper.Agent-7284412-0 by ClamAV, indicating it functions as a dropper. The presence of multiple external URLs within the document suggests an attempt to redirect the user to download further malicious content. The document body itself is heavily obfuscated and does not provide clear textual lures, but the heuristic firings and embedded URLs strongly indicate a malicious dropper functionality.

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7284412-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7284412-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/the-stormrider-guide-europe-the-continent-stormrider-surf-guides-english.pdf
    • http://www.gorillawalker.com/super-safari-level-2-posters-10.pdf
    • http://www.gorillawalker.com/orange-alert-executioner.pdf
    • http://www.gorillawalker.com/free-travel-my-20-years-travel-in-taiwan-chinese-edition.pdf
    • http://www.gorillawalker.com/the-gmax-handbook-game-development-series.pdf
    • http://www.gorillawalker.com/the-thousand-correct-actions-of-the-upright-soldier.pdf
    • http://www.gorillawalker.com/cispr-16-2-2-ed-1-2-b-2005-specification.pdf
    • http://www.gorillawalker.com/student-solutions-manual-for-barnett-ziegler-and-byleen-s-analytic.pdf
    • http://www.gorillawalker.com/from-russia-with-love-james-bond-series.pdf
    • http://www.gorillawalker.com/clowns-on-the-bus.pdf
    • http://www.gorillawalker.com/edward-vi-the-lost-king-of-england.pdf
    • http://www.gorillawalker.com/intelligence-integration-in-distributed-knowledge-management.pdf
    • http://www.gorillawalker.com/travels-in-tartary-thibet-and-china-during-the-years-1844.pdf
    • http://www.gorillawalker.com/bangladesh-sudoc-prex-3-10-4-b-22-2.pdf
    • http://www.gorillawalker.com/memoirs-of-hecate-county-new-york-review-books-classics.pdf
    • http://www.gorillawalker.com/rational-choice-in-an-uncertain-world-the-psychology-of-judgment.pdf
    • http://www.gorillawalker.com/encyclopedia-of-retirement-and-finance-two-volumes.pdf
    • http://www.gorillawalker.com/economics-in-one-lesson.pdf
    • http://www.gorillawalker.com/v83s-successful-warmups-book-1-singers-edition.pdf
    • http://www.gorillawalker.com/ancient-greece-the-famous-monuments-past-and-present.pdf
    • http://www.gorillawalker.com/classic-mosaic.pdf
    • http://www.gorillawalker.com/don-t-kill-him-the-story-of-my-life-with.pdf
    • http://www.gorillawalker.com/twenty-count-secret-mathematical-system-of-the-aztec-maya.pdf
    • http://www.gorillawalker.com/credit-risk-management-basic-concepts.pdf
    • http://www.gorillawalker.com/once-on-this-island.pdf
    • http://www.gorillawalker.com/variety-international-film-guide-2000.pdf
    • http://www.gorillawalker.com/autocad-platform-customization-vba.pdf
    • http://www.gorillawalker.com/acoustic-cavitation-theory-equipment-design-principles-for-industrial-applications-of.pdf
    • http://www.gorillawalker.com/renaissance-talk-ordinary-language-and-the-mystique-of-critical-problems.pdf
    • http://www.gorillawalker.com/von-der-hauptstadtposse-zur-erfolgsgeschichte-die-entstehung-des-judischen-museums.pdf
    • http://www.gorillawalker.com/mr-tibbs-goes-to-switzerland-fun-time-for-kids-volume.pdf
    • http://www.gorillawalker.com/south-african-special-forces-elite.pdf
    • http://www.gorillawalker.com/niosh-health-hazard-evaluation-report-heta-2005-0290-2992-united.pdf
    • http://www.gorillawalker.com/confession-of-the-lioness.pdf
    • http://www.gorillawalker.com/glutathione-the-secret-antioxidant-to-prevent-cancer-aging-dementia-and.pdf
    • http://www.gorillawalker.com/from-nursing-assistant-to-clinical-care-associate.pdf
    • http://www.gorillawalker.com/realms-of-the-dead-a-forgotten-realms-anthology-the-haunted.pdf
    • http://www.gorillawalker.com/by-david-hanes-fax-modem-and-text-for-ip-telephony.pdf
    • http://www.gorillawalker.com/gravitational-solitons-cambridge-monographs-on-mathematical-physics.pdf
    • http://www.gorillawalker.com/the-american-salad-book-1900.pdf
    • http://www.gorillawalk
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/