Malicious PDF — malware analysis report

Static analysis result for SHA-256 985ab0a0e705d94d…

MALICIOUS

PDF

43.6 KB Created: 2018-11-23 08:06:22 +03:00 Authoring application: - (via Python PDF Library - http://pybrary.net/pyPdf/)
MD5: f36867fd0065d67b889c959e702af314 SHA-1: 463ccfb9d89a795b94d1cb4db8df29f1288b7691 SHA-256: 985ab0a0e705d94da315b407ea12f00d89e877a3f072d4d79afb9b1412833cdc
92 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious Link

The file was detected by ClamAV as Pdf.Dropper.Agent-7285070-0 and flagged by an ML classifier, indicating malicious intent. The PDF contains numerous external URIs pointing to various documents on the gorillawalker.com domain. These URIs are likely used to lure the user into downloading additional malicious content, acting as a dropper.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9171

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7285070-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7285070-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/indus-saga-and-the-making-of-pakistan.pdf
    • http://www.gorillawalker.com/stephen-king-from-a-to-z-an-encyclopedia-of-his.pdf
    • http://www.gorillawalker.com/the-art-of-marine-painting-in-oil-colours.pdf
    • http://www.gorillawalker.com/the-slums-of-palo-alto-preview-how-to-be-ecstatically.pdf
    • http://www.gorillawalker.com/surviving-australia-a-practical-guide-to-staying-alive.pdf
    • http://www.gorillawalker.com/the-art-of-recognition-in-wolfram-s-parzival.pdf
    • http://www.gorillawalker.com/fernsehkameras-die-komplette-technik-ideen-erfindungen-german-edition-kindle-edition.pdf
    • http://www.gorillawalker.com/in-conversation-with-cinematographers.pdf
    • http://www.gorillawalker.com/the-murder-farm.pdf
    • http://www.gorillawalker.com/first-among-equals-how-to-manage-a-group-of-professionals.pdf
    • http://www.gorillawalker.com/the-babysitter-and-me-my-world.pdf
    • http://www.gorillawalker.com/handel-psalm-112-vocal-score-edition-peters-no-3762.pdf
    • http://www.gorillawalker.com/proverbs-words-of-wisdom.pdf
    • http://www.gorillawalker.com/advanced-soil-dynamics-and-earthquake-engineering-print-replica-kindle-edition.pdf
    • http://www.gorillawalker.com/successful-investing-and-money-management.pdf
    • http://www.gorillawalker.com/the-agamemnon-of-aeschylus.pdf
    • http://www.gorillawalker.com/death-note-vol-4.pdf
    • http://www.gorillawalker.com/the-courts-of-jamaica-and-their-jurisdiction.pdf
    • http://www.gorillawalker.com/that-old-time-religion-the-story-of-religious-foundations.pdf
    • http://www.gorillawalker.com/extreme-coloring-the-ultimate-search-and-find-coloring-book.pdf
    • http://www.gorillawalker.com/road-to-communism-the-rise-and-fall-of-the-soviet.pdf
    • http://www.gorillawalker.com/taken-with-the-vampires-vol-1-a-vampiric-faith-short.pdf
    • http://www.gorillawalker.com/soul-hunter-warhammer-40-000-novels.pdf
    • http://www.gorillawalker.com/jim-carrey-fun-and-funnier.pdf
    • http://www.gorillawalker.com/time-reborn-from-the-crisis-in-physics-to-the-future.pdf
    • http://www.gorillawalker.com/uncommon-grounds-the-history-of-coffee-and-how-it-transformed.pdf
    • http://www.gorillawalker.com/barnes-noble-health-basics-menopause-barnes-noble-basics-by-loos.pdf
    • http://www.gorillawalker.com/insight-guides-sardinia.pdf
    • http://www.gorillawalker.com/responses-to-terrorism-can-psychosocial-approaches-break-the-cycle-of.pdf
    • http://www.gorillawalker.com/todavia-estoy-aqui-spanish-edition.pdf
    • http://www.gorillawalker.com/gothic-renaissance-a-reassessment.pdf
    • http://www.gorillawalker.com/trife-life-to-lavish-a-king-production-presents.pdf
    • http://www.gorillawalker.com/haunted-mantorville-trailing-the-ghosts-of-old-minnesota.pdf
    • http://www.gorillawalker.com/college-algebra-with-modeling-and-visualization-custom-edition-for-macon.pdf
    • http://www.gorillawalker.com/the-blue-book-manual-of-nigritian-history-american-descendants-of.pdf
    • http://www.gorillawalker.com/baby-names-keepsake.pdf
    • http://www.gorillawalker.com/a-dozen-orgies-latin-american-plays-of-the-twentieth-century.pdf
    • http://www.gorillawalker.com/disciple-becoming-disciples-through-bible-study-study-manual.pdf
    • http://www.gorillawalker.com/from-concept-to-customer-portfolio-pipeline-and-strategic-project-management.pdf
    • http://www.gorillawalker.com/portrait-of-a-marriage-a-novel-kindle-edition.pdf
    • http://pybrary.net/pyPdf/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/