Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb854d8db7ba03f3…

MALICIOUS

PDF

41.5 KB Created: 2018-11-23 21:03:27 +03:00 Authoring application: Adobe InDesign CS3 (5.0.2) (via Adobe PDF Library 8.0)
MD5: 8c54b015d222a58660fc83ee61de9723 SHA-1: 77567253cd2ffe4a0c72ebca015df8e039b39c15 SHA-256: cb854d8db7ba03f3a3102eaeccd631b8728e35faec53d048a6a7c27545b8db0c
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious Link

The ClamAV heuristic identified this PDF as a dropper, and it contains multiple embedded URLs pointing to other PDF files. The presence of these external links suggests the document is designed to redirect users to potentially malicious content hosted on the gorillawalker.com domain. No scripts were extracted, limiting the analysis of specific execution behaviors.

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7304421-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7304421-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/beijing-tour-guide.pdf
    • http://www.gorillawalker.com/easy-vegetarian-slow-cooker-cookbook-125-fix-and-forget-vegetarian.pdf
    • http://www.gorillawalker.com/phantom-illness-shattering-the-myth-of-hypochondria.pdf
    • http://www.gorillawalker.com/for-the-public-good-forced-sterilization-and-the-fight-for.pdf
    • http://www.gorillawalker.com/and-china-has-hands.pdf
    • http://www.gorillawalker.com/california-and-oregon-or-sights-in-the-gold-region-and.pdf
    • http://www.gorillawalker.com/big-daddy-sinatra-there-was-a-ruthless-man-the-sinatras.pdf
    • http://www.gorillawalker.com/fodor-montreal-91.pdf
    • http://www.gorillawalker.com/a-digital-facsimile-of-terence-s-comedies-bodleian-digital-texts.pdf
    • http://www.gorillawalker.com/irish-records-sources-for-family-and-local-history-revised-edition.pdf
    • http://www.gorillawalker.com/virginia-hello-u-s-a.pdf
    • http://www.gorillawalker.com/101-ways-to-work-out-on-the-ball-sculpt-your.pdf
    • http://www.gorillawalker.com/the-encyclopedia-of-novels-into-film-facts-on-file-film.pdf
    • http://www.gorillawalker.com/tyrannosaurus-brighter-child-read-paint-and-play.pdf
    • http://www.gorillawalker.com/myself-together-again-book-i-myself-together-again.pdf
    • http://www.gorillawalker.com/northern-travel-summer-and-winter-pictures-of-sweden-denmark-and.pdf
    • http://www.gorillawalker.com/world-sound-matters-teacher-packet.pdf
    • http://www.gorillawalker.com/stresses-in-plates-and-shells.pdf
    • http://www.gorillawalker.com/mi-carina-diego-s-wrath-mi-carino-carina-series-book.pdf
    • http://www.gorillawalker.com/algebra-and-trigonometry-with-modeling-visualization.pdf
    • http://www.gorillawalker.com/race-evolution-and-behavior-a-life-history-perspective.pdf
    • http://www.gorillawalker.com/nascar-kids-jumbo-coloring-activity.pdf
    • http://www.gorillawalker.com/never-get-drunk-in-a-tranny-bar-kindle-edition.pdf
    • http://www.gorillawalker.com/transnational-childhoods-british-bangladeshis-identities-and-social-change-studies-in.pdf
    • http://www.gorillawalker.com/the-parrotfishes-of-the-subfamily-scarinae-of-the-western-indian.pdf
    • http://www.gorillawalker.com/eat-well-get-healthy.pdf
    • http://www.gorillawalker.com/the-fire-beaks-crusade-vol-4.pdf
    • http://www.gorillawalker.com/beitr-ge-zur-begriffsgeschichte-der-italienischen-aufkl-rung-im-europ.pdf
    • http://www.gorillawalker.com/california-the-geography-of-diversity.pdf
    • http://www.gorillawalker.com/hungry-for-trade-how-the-poor-pay-for-free-trade.pdf
    • http://www.gorillawalker.com/recital-program-blanks-55-roses-and-keyboard.pdf
    • http://www.gorillawalker.com/desert-boats-predynastic-and-pharaonic-era-rock-art-in-egypt.pdf
    • http://www.gorillawalker.com/out-doors-at-idlewild-or-the-shaping-of-a-home.pdf
    • http://www.gorillawalker.com/tough-lessons-unabridged-audible-audio-edition.pdf
    • http://www.gorillawalker.com/footfree-and-fancyloose.pdf
    • http://www.gorillawalker.com/horses-2010-calendar.pdf
    • http://www.gorillawalker.com/captain-tomahawk-and-the-sky-lion.pdf
    • http://www.gorillawalker.com/reading-ancient-texts-presocratics-and-plato-essays-in-honour-of.pdf
    • http://www.gorillawalker.com/beethoven-symphonies-a-guided-tour-unlocking-the-masters-series-book.pdf
    • http://www.gorillawalker.com/child-prodigies-fink-still-at-large-an-article-from-clinical.pdf
    • http://www.gorillawalker.com/big-daddy-sinatra-there-was-a-ruthless-man-the-sin
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/