Malicious PDF — malware analysis report

Static analysis result for SHA-256 b96e034dd9ec6faf…

MALICIOUS

PDF

42.1 KB Created: 2019-02-12 10:24:27 +03:00 Authoring application: Adobe Acrobat 8.0 (via Adobe Acrobat 8.0 Image Conversion Plug-in)
MD5: 036107bd80430d42629712aba6144185 SHA-1: ccf81a29e2da164c17f2d552f0993eaf528a99c3 SHA-256: b96e034dd9ec6faf6117f53d0b6cd28e1127d699aee334f4c4b4d7b85729ed77
92 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious Link T1566.002 Spearphishing Attachment

The file was detected as malicious by ClamAV (Pdf.Dropper.Agent-7147908-0) and flagged by an ML classifier. It contains multiple embedded URLs pointing to PDF files on the same domain, suggesting a dropper mechanism. The primary attack pattern involves luring the user to click on a link within the PDF, which then likely leads to the download of a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9027

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7147908-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7147908-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/contemporary-maternal-newborn-nursing-plus-new-mynursinglab-with-pearson-etext.pdf
    • http://www.gorillawalker.com/sticky-beak.pdf
    • http://www.gorillawalker.com/let-s-kanikapila-ten-steps-to-learn-ukulele-the-hawaiian.pdf
    • http://www.gorillawalker.com/taking-his-big-delivery-unprotected-and-stretched-super-hung-short.pdf
    • http://www.gorillawalker.com/mastering-the-basics-of-photography.pdf
    • http://www.gorillawalker.com/money-series-b-norvik-press.pdf
    • http://www.gorillawalker.com/air-crashes-and-miracle-landings-60-narratives-how-when-and.pdf
    • http://www.gorillawalker.com/versos-diversos-spanish-edition-kindle-edition.pdf
    • http://www.gorillawalker.com/travel-and-talk-1885-93-95-my-hundred-thousand-miles.pdf
    • http://www.gorillawalker.com/la-guerra-de-los-yacares-cuentos-de-la-selva-spanish.pdf
    • http://www.gorillawalker.com/baroque-music-today-music-as-speech-ways-to-a-new.pdf
    • http://www.gorillawalker.com/a-confederation-of-valor-valor-novel.pdf
    • http://www.gorillawalker.com/ommi-sissi-gattous-the-cat-a-folk-tale-for-children.pdf
    • http://www.gorillawalker.com/digital-product-and-product-data-management.pdf
    • http://www.gorillawalker.com/iec-60424-2-ed-1-0-b-1997-guidance-of.pdf
    • http://www.gorillawalker.com/tidewater-inn-hope-beach.pdf
    • http://www.gorillawalker.com/clarinet-quartets-for-beginners-volume-1-for-4-clarinets-or.pdf
    • http://www.gorillawalker.com/princess-sonora-and-the-long-sleep-princess-tales.pdf
    • http://www.gorillawalker.com/insight-travel-maps-bulgaria-romania-moldova-macedonia-eastern-serbia.pdf
    • http://www.gorillawalker.com/the-mystery-of-the-blue-train-a-hercule-poirot-mystery.pdf
    • http://www.gorillawalker.com/eyelid-conjunctival-and-orbital-tumors-an-atlas-and-text.pdf
    • http://www.gorillawalker.com/best-deal-s-in-pattaya-thailand-shopping-volume-1.pdf
    • http://www.gorillawalker.com/tanys-gladiatrix-the-chronicles-of-tanys-book-2-kindle-edition.pdf
    • http://www.gorillawalker.com/new-world-order-the-rise-of-the-police-state-in.pdf
    • http://www.gorillawalker.com/a-fire-on-the-moon.pdf
    • http://www.gorillawalker.com/a-history-of-the-arabs-in-the-sudan-and-some.pdf
    • http://www.gorillawalker.com/permission-marketing-abridged-audible-audio-edition.pdf
    • http://www.gorillawalker.com/juan-salvador-gaviota-nueva-edici-n-spanish-edition.pdf
    • http://www.gorillawalker.com/contemporary-oral-and-maxillofacial-surgery.pdf
    • http://www.gorillawalker.com/classical-lullabies-mozart-and-other-masters-kidzup-lullabies.pdf
    • http://www.gorillawalker.com/beggars-or-angels.pdf
    • http://www.gorillawalker.com/greek-fiction-callirhoe-daphnis-and-chloe-letters-of-chion-penguin.pdf
    • http://www.gorillawalker.com/an-invitation-to-devon.pdf
    • http://www.gorillawalker.com/the-orthodontic-mini-implant-clinical-handbook-1st-edition-by-cousley.pdf
    • http://www.gorillawalker.com/getting-to-the-core-of-english-language-arts-grades-6.pdf
    • http://www.gorillawalker.com/seductive-poison-a-jonestown-survivor-s-story-of-life-and.pdf
    • http://www.gorillawalker.com/the-gothic-line-italy-winter-1944.pdf
    • http://www.gorillawalker.com/the-view-from-mount-calvary-24-portraits-of-the-cross.pdf
    • http://www.gorillawalker.com/beisbol-en-abril-y-otras-historias-spanish-edition.pdf
    • http://www.gorillawalker.com/acting-a-modern-history-of-filmmaking-behind-the-silver-screen.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/