Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9f0e6ed35081eaf…

MALICIOUS

PDF

34.3 KB Created: 2019-09-30 03:01:55 +03:00 Authoring application: QuarkXPress(R) 8.0
MD5: 436942529be860fc2fc139fbe2514ff4 SHA-1: 446ed0b78c8d612123a85273a7a45844acbbf6bb SHA-256: d9f0e6ed35081eaf5fccaef2fcae95e92a2f041a87b6f4369e0ea6474eb2eeed
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The file is identified as a PDF dropper by ClamAV. Static analysis revealed multiple embedded URLs pointing to external websites. The presence of these URLs suggests the document is designed to redirect users to potentially malicious content or download further payloads. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7330829-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7330829-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/eat-your-world-s-new-york-city-food-travel-guide.pdf
    • http://www.gorillawalker.com/witnessing-the-holocaust-the-dutch-in-wartime-survivors-remember.pdf
    • http://www.gorillawalker.com/bill-reid.pdf
    • http://www.gorillawalker.com/on-the-trail-of-the-truth-journals-of-corrie-belle.pdf
    • http://www.gorillawalker.com/the-winter-of-red-snow-the-revolutionary-war-diary-of.pdf
    • http://www.gorillawalker.com/cairo-popout-map.pdf
    • http://www.gorillawalker.com/the-haunted-school-goosebumps-59.pdf
    • http://www.gorillawalker.com/making-enterprise-risk-management-pay-off-how-leading-companies-implement.pdf
    • http://www.gorillawalker.com/emerging-compounds-removal-from-wastewater-natural-and-solar-based-treatments.pdf
    • http://www.gorillawalker.com/fractional-order-systems-and-controls-fundamentals-and-applications-advances-in.pdf
    • http://www.gorillawalker.com/io-sono-piccola-una-storia-illustrata-di-philipp-winterberg-e.pdf
    • http://www.gorillawalker.com/the-papers-of-martin-luther-king-jr-volume-iii-birth.pdf
    • http://www.gorillawalker.com/math-workout-for-the-gmat-5th-edition-graduate-school-test.pdf
    • http://www.gorillawalker.com/byjames-p-clements-by-jack-gido-successful-project-management-with.pdf
    • http://www.gorillawalker.com/a-life-in-movies.pdf
    • http://www.gorillawalker.com/guide-to-cost-of-capital-2014-wiley-finance.pdf
    • http://www.gorillawalker.com/microbiology-for-health-careers.pdf
    • http://www.gorillawalker.com/ultimate-guide-to-google-adwords-how-to-access-100-million.pdf
    • http://www.gorillawalker.com/the-private-pilot-s-licence-course-flying-training-bk-1.pdf
    • http://www.gorillawalker.com/the-black-hole-of-public-administration-governance-series.pdf
    • http://www.gorillawalker.com/collaborative-consultation-in-the-schools-effective-practices-for-students-with.pdf
    • http://www.gorillawalker.com/the-farthest-shore-earthsea-cycle.pdf
    • http://www.gorillawalker.com/the-life-of-luther.pdf
    • http://www.gorillawalker.com/pathways-3-listening-speaking-and-critical-thinking-pathways-listening-speaking.pdf
    • http://www.gorillawalker.com/evan-s-book-of-trickery-book-1-magic-more.pdf
    • http://www.gorillawalker.com/the-wild-and-exciting-world-of-snow-boarding.pdf
    • http://www.gorillawalker.com/lydia-s-hypnosis-lesbian-mind-control-erotica.pdf
    • http://www.gorillawalker.com/the-power-of-positive-thinking-in-business-ten-traits-for.pdf
    • http://www.gorillawalker.com/trespass-a-history-of-uncommissioned-urban-art-hardback-common.pdf
    • http://www.gorillawalker.com/don-t-breathe-a-word-a-novel.pdf
    • http://www.gorillawalker.com/the-pledge-of-allegiance-let-s-see-library-our-nation.pdf
    • http://www.gorillawalker.com/dictionary-of-real-estate-terms-barron-s-business-dictionaries.pdf
    • http://www.gorillawalker.com/civics-flash-cards-for-the-naturalization-test-2012-english-version.pdf
    • http://www.gorillawalker.com/agricultural-urbanism-handbook-for-building-sustainable-food-systems-in-21st.pdf
    • http://www.gorillawalker.com/read-his-hands-know-his-heart-mega-kit-mega-mini.pdf
    • http://www.gorillawalker.com/better-homes-and-gardens-all-time-favorite-fish-and-seafood.pdf
    • http://www.gorillawalker.com/digital-design-with-rtl-design-verilog-and-vhdl-by-vahid.pdf
    • http://www.gorillawalker.com/threads-of-time-recollections.pdf
    • http://www.gorillawalker.com/better-homes-and-gardens-party-foods-2012.pdf
    • http://www.gorillawalker.com/william-at-war-just-william-series.pdf
    • http://www.gorillawalker.com/io-sono-piccola-una-storia-illustrata-di-philipp
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/