Malicious PDF — malware analysis report

Static analysis result for SHA-256 ad741823fe58d2fa…

MALICIOUS

PDF

43.1 KB Created: 2019-02-13 20:55:27 +03:00 Authoring application: FrameMaker 10.0.2 (via Acrobat Distiller 10.1.15 (Windows))
MD5: d40622906d86e5a0aa5966c4146d99cc SHA-1: 5a2bc7ddb3e2f154587643716a0390f79cc6c3f3 SHA-256: ad741823fe58d2faf8c02a502bb205518776cadb4c5e7b851af36d4cd35cf469
92 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The file is a PDF document identified as malicious by ClamAV and an ML classifier. It contains multiple embedded URLs pointing to PDF files on the 'gorillawalker.com' domain. The presence of these URLs suggests the document's primary purpose is to trick the user into downloading further malicious content. The document body itself is heavily obfuscated and does not provide direct textual clues, but the embedded URLs are clear indicators of a download lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9027

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7142158-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7142158-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/the-pooring-of-america-competition-and-the-myth-of-free.pdf
    • http://www.gorillawalker.com/the-double-cross-system-the-classic-account-of-world-war.pdf
    • http://www.gorillawalker.com/breaking-god-into-prison-how-to-successfully-transition-from-incarceration.pdf
    • http://www.gorillawalker.com/the-white-girl-kindle-edition.pdf
    • http://www.gorillawalker.com/the-shapeshifter-s-secret.pdf
    • http://www.gorillawalker.com/student-solutions-for-calculus-and-analytic-geometry-second-edition-chapters.pdf
    • http://www.gorillawalker.com/volcano-under-snow.pdf
    • http://www.gorillawalker.com/mini-pies-sweet-and-savory-recipes-for-the-electric-pie.pdf
    • http://www.gorillawalker.com/becoming-better-parents.pdf
    • http://www.gorillawalker.com/secure-discovering-true-financial-freedom-new-edition.pdf
    • http://www.gorillawalker.com/even-odds.pdf
    • http://www.gorillawalker.com/la-sociedad-de-iguales-spanish-edition-kindle-edition.pdf
    • http://www.gorillawalker.com/reclaim-your-heart.pdf
    • http://www.gorillawalker.com/defiled-by-the-board-room-group-first-time-unprotected-defiled.pdf
    • http://www.gorillawalker.com/chemical-sensitivity-tools-diagnosis-and-method-of-treatment-volume-iv.pdf
    • http://www.gorillawalker.com/postville-usa-surviving-diversity-in-small-town-america.pdf
    • http://www.gorillawalker.com/a-jew-to-the-jews-jewish-contours-of-pauline-flexibility.pdf
    • http://www.gorillawalker.com/business-consulting-services-korean-edition.pdf
    • http://www.gorillawalker.com/geometrical-aspects-of-functional-analysis-israel-seminar-1985-86-lecture.pdf
    • http://www.gorillawalker.com/financial-managerial-accounting-with-connect-plus-by-williams-jan-published.pdf
    • http://www.gorillawalker.com/nada-official-used-car-guide-eastern-edition-2005-through-2012.pdf
    • http://www.gorillawalker.com/everything-you-want-to-know-about-organisational-change-everything-you.pdf
    • http://www.gorillawalker.com/how-to-be-your-own-investment-counselor-through-the-use.pdf
    • http://www.gorillawalker.com/dimensions-of-adult-learning.pdf
    • http://www.gorillawalker.com/allegro-al-dente.pdf
    • http://www.gorillawalker.com/sunlight-in-new-granada.pdf
    • http://www.gorillawalker.com/keto-diet-smoothies-and-shakes-ketogenic-diet-recipes-for-weight.pdf
    • http://www.gorillawalker.com/hockey-hair.pdf
    • http://www.gorillawalker.com/scale-speller-level-2-schaum-publications.pdf
    • http://www.gorillawalker.com/30-minute-social-media-marketing-step-by-step-techniques-to.pdf
    • http://www.gorillawalker.com/wrongful-conviction-a-jean-jankowski-mystery.pdf
    • http://www.gorillawalker.com/having-fun-over-bristol-world-capital-of-hot-air-ballooning.pdf
    • http://www.gorillawalker.com/go-with-office-2013-volume-1-go-with-internet-explorer.pdf
    • http://www.gorillawalker.com/liberating-shahrazad-feminism-postcolonialism-and-islam-posthumanities.pdf
    • http://www.gorillawalker.com/bedeutende-briefe-die-au-ergew-hnlichsten-deutschen-schrifst-cke-german.pdf
    • http://www.gorillawalker.com/mexico-the-people-lands-peoples-cultures.pdf
    • http://www.gorillawalker.com/managing-the-environment-for-diverse-recreation-cross-country-skiing-in.pdf
    • http://www.gorillawalker.com/handbook-of-human-development-for-health-care-professionals.pdf
    • http://www.gorillawalker.com/by-maeve-cummings-by-stephen-haag-management-information-systems-for.pdf
    • http://www.gorillawalker.com/johnny-orient-express-chan-superstars-of-poker.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/