Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca345f78830cfe88…

MALICIOUS

PDF

42.7 KB Created: 2018-12-28 08:08:53 +03:00 Authoring application: ZonBook XSL Stylesheets with Apache FOP (via Apache FOP Version 2.1)
MD5: b9c1886b5e07f282075caf1c88fd3b39 SHA-1: dfc5b94214ab5ca6f0b7f120458f4581bbd2d079 SHA-256: ca345f78830cfe88a66b25530a378fefeb55b142e6b7405f19093a23c90c0e50
72 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by an ML classifier and contains heuristics indicating an advance-fee scam lure. The document body, though heavily obfuscated, contains embedded URLs that are likely part of the scam. The primary attack pattern involves tricking the user into believing they have won a prize or are eligible for a large sum of money, which requires them to pay a fee for parcel delivery or processing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8872

Heuristics 3

  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/den-gamle-by-a-window-into-the-past.pdf
    • http://www.gorillawalker.com/workers-compensation-laws-of-california-2011.pdf
    • http://www.gorillawalker.com/basher-science-the-periodic-table-elements-with-style.pdf
    • http://www.gorillawalker.com/the-knitted-rug-21-fantastic-designs.pdf
    • http://www.gorillawalker.com/the-big-dance-the-story-of-the-ncaa-basketball-tournament.pdf
    • http://www.gorillawalker.com/new-orleans-nocturnal-kindle-edition.pdf
    • http://www.gorillawalker.com/woman-s-life-and-love-frauenliebe-und-leben-high-voice.pdf
    • http://www.gorillawalker.com/integrated-branding.pdf
    • http://www.gorillawalker.com/fodor-s-thailand-7th-edition-where-to-stay-eat-and.pdf
    • http://www.gorillawalker.com/unique-power-system-problems-solved.pdf
    • http://www.gorillawalker.com/ressourcement-thomism-sacred-doctrine-the-sacraments-and-the-moral-life.pdf
    • http://www.gorillawalker.com/by-lippincott-williams-wilkins-stedman-s-ophthalmology-words-4th-fourth.pdf
    • http://www.gorillawalker.com/la-3a-alternativa-spanish-edition.pdf
    • http://www.gorillawalker.com/reducing-the-risk-a-school-leader-s-guide-to-aids.pdf
    • http://www.gorillawalker.com/what-is-the-legislative-branch-your-guide-to-government.pdf
    • http://www.gorillawalker.com/don-t-just-retire-live-it-love-it.pdf
    • http://www.gorillawalker.com/the-game-of-chess-by-carlo-goldoni.pdf
    • http://www.gorillawalker.com/pocket-guide-to-clinical-microbiology.pdf
    • http://www.gorillawalker.com/spider-woman-s-daughter-leaphorn-and-chee-mysteries-book-19.pdf
    • http://www.gorillawalker.com/aboriginal-australians-indigenous-peoples.pdf
    • http://www.gorillawalker.com/the-harmonic-conquest-of-space-lost-science-series.pdf
    • http://www.gorillawalker.com/lizzie-s-war.pdf
    • http://www.gorillawalker.com/the-life-of-mohammad-from-original-sources.pdf
    • http://www.gorillawalker.com/the-women-s-health-big-book-of-abs-sculpt-a.pdf
    • http://www.gorillawalker.com/classroom-assessment-for-students-in-special-and-general-education-3rd.pdf
    • http://www.gorillawalker.com/three-years-among-the-comanches-the-narrative-of-nelson-lee.pdf
    • http://www.gorillawalker.com/key-management-models-the-60-models-every-manager-needs-to.pdf
    • http://www.gorillawalker.com/biophotonics-for-medical-applications-woodhead-publishing-series-in-biomaterials.pdf
    • http://www.gorillawalker.com/the-essential-gluten-free-grocery-guide-6th-edition-kindle-edition.pdf
    • http://www.gorillawalker.com/good-calories-bad-calories-challenging-the-conventional-wisdom-on-diet.pdf
    • http://www.gorillawalker.com/captured-arms-beutewaffen-propaganda-photo.pdf
    • http://www.gorillawalker.com/now-that-you-ve-gone-home-courage-and-comfort-for.pdf
    • http://www.gorillawalker.com/reactive-drug-metabolites-volume-55.pdf
    • http://www.gorillawalker.com/matrimonio-de-amor-matrimonio-de-estado-vida-de-alfonso-xii.pdf
    • http://www.gorillawalker.com/joe-the-slave-who-became-an-alamo-legend.pdf
    • http://www.gorillawalker.com/the-illumination-a-novel-kindle-edition.pdf
    • http://www.gorillawalker.com/those-pullman-blues-an-oral-history-of-the-african-american.pdf
    • http://www.gorillawalker.com/beginning-ubuntu-linux-for-windows-and-mac-users.pdf
    • http://www.gorillawalker.com/the-printing-press-a-breakthrough-in-communication-point-of-impact.pdf
    • http://www.gorillawalker.com/bmw-3-series-e90-e91-e92-e93-service-manual-2006.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/