Malicious PDF — malware analysis report

Static analysis result for SHA-256 c6598f1886d433d9…

MALICIOUS

PDF

42.2 KB Created: 2018-11-23 21:05:20 +03:00 Authoring application: LaTeX with hyperref package (via pdfTeX-1.40.16)
MD5: 9d168abf38c7a6d9b1b3267b6a8e2af0 SHA-1: 8ed7fe30050e8ca8f56071b26ea42f21a2dfecce SHA-256: c6598f1886d433d95af1becf7b38457b34e1da3caf4803f748f7700c545fbc1f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.001 PowerShell

The file was detected by ClamAV as Pdf.Dropper.Agent-7301618-0 and flagged by an ML classifier, indicating malicious intent. The presence of multiple external URIs, including http://www.gorillawalker.com/woman-without-a-past.pdf, suggests the PDF acts as a dropper for further malicious content. The document body contains obfuscated text and embedded URLs, consistent with a payload delivery mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8872

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7301618-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7301618-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/woman-without-a-past.pdf
    • http://www.gorillawalker.com/passion-line-photographs-of-dancers.pdf
    • http://www.gorillawalker.com/barnabas.pdf
    • http://www.gorillawalker.com/the-bronze-bow-turtleback-school-library-binding-edition.pdf
    • http://www.gorillawalker.com/love-for-the-vampire.pdf
    • http://www.gorillawalker.com/the-funniest-excuse-book-ever.pdf
    • http://www.gorillawalker.com/germany-s-third-empire.pdf
    • http://www.gorillawalker.com/total-communication-structure-and-strategy.pdf
    • http://www.gorillawalker.com/white-tigress.pdf
    • http://www.gorillawalker.com/matter-energy-and-heat-facts-at-your-fingertips.pdf
    • http://www.gorillawalker.com/learning-to-walk-in-the-dark-because-god-often-shows.pdf
    • http://www.gorillawalker.com/le-ventre-de-paris-french-edition.pdf
    • http://www.gorillawalker.com/backpack-literature-an-introduction-to-fiction-poetry-drama-and-writing.pdf
    • http://www.gorillawalker.com/spelling-writing-grade-1-home-workbooks.pdf
    • http://www.gorillawalker.com/chosen-graphic-novel-the-lost-books-series-book-1.pdf
    • http://www.gorillawalker.com/pmp-217-success-secrets-217-most-asked-questions-on-pmp.pdf
    • http://www.gorillawalker.com/the-proof-and-the-pudding-what-mathematicians-cooks-and-you.pdf
    • http://www.gorillawalker.com/feeling-good-the-new-mood-therapy-revised-and-updated-feeling.pdf
    • http://www.gorillawalker.com/the-year-s-best-science-fiction-fantasy-novellas-2015.pdf
    • http://www.gorillawalker.com/anti-intellectualism-and-the-education-of-high-ability-learners-kindle.pdf
    • http://www.gorillawalker.com/angelina-ballerina-puzzle.pdf
    • http://www.gorillawalker.com/shanell-lashawn-knight-valentina-monee-carter-cartell-crawford-the-babies.pdf
    • http://www.gorillawalker.com/slow-burn-dominant-firefighters-bbw-bdsm-erotic-power-romance.pdf
    • http://www.gorillawalker.com/confessions-of-a-mad-man-the-crusaders-justice-above-all.pdf
    • http://www.gorillawalker.com/florida-butterfly-caterpillars-and-their-host-plants.pdf
    • http://www.gorillawalker.com/navratri-special-no-onion-no-garlic.pdf
    • http://www.gorillawalker.com/aleks-user-s-guide-access-code.pdf
    • http://www.gorillawalker.com/entrance-into-the-novitiate-by-clerics-in-major-orders-1953.pdf
    • http://www.gorillawalker.com/iso-15214-1998-microbiology-of-food-and-animal-feeding-stuffs.pdf
    • http://www.gorillawalker.com/architectural-graphic-standards-7th-edition-7th-edition-by-ramsey-charles.pdf
    • http://www.gorillawalker.com/dragonart-drawing-workshop-dvd-series-today-s-artist.pdf
    • http://www.gorillawalker.com/life-and-death-responsibilities-in-jewish-biomedical-ethics.pdf
    • http://www.gorillawalker.com/robert-s-rule-of-order.pdf
    • http://www.gorillawalker.com/cornered-a-bullying-story-about-a-square-shelled-turtle-kindle.pdf
    • http://www.gorillawalker.com/big-book-of-beautiful-afghans.pdf
    • http://www.gorillawalker.com/220-sex-pictures-naked-women-shaved-pussy-breasts-in-illinois.pdf
    • http://www.gorillawalker.com/linguistics-of-american-sign-language-5th-ed-an-introduction.pdf
    • http://www.gorillawalker.com/zenith-rising.pdf
    • http://www.gorillawalker.com/when-tutor-meets-student.pdf
    • http://www.gorillawalker.com/vice-presidents-a-biographical-dictionary.pdf
    • http://www.gorillawalker.com/backpack-literature-an-introduction-to-fiction-poetry-drama-a
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/