Malicious PDF — malware analysis report

Static analysis result for SHA-256 deb4f1798da66462…

MALICIOUS

PDF

32.8 KB Created: 2019-09-08 11:53:12 +03:00 Authoring application: Adobe InDesign CC (Macintosh) (via Adobe PDF Library 11.0)
MD5: 9aa9bf8cde88d14d779e053e46da2283 SHA-1: 39dd92caedd8ec6cf4906ccd2acfc61b6a49dd4e SHA-256: deb4f1798da664628b1a42d8fa3b3e96d8cba174e56124a95a2bafce520e9464
92 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious Link

The file is identified as a malicious PDF dropper by ClamAV and an ML classifier. It contains an embedded URI pointing to a PDF file on 'gorillawalker.com'. The document body is heavily obfuscated and unreadable, but the presence of the external URI strongly suggests the intent is to trick the user into downloading and opening a secondary malicious document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8313

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7369764-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7369764-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/precious-moments-animal-kingdom.pdf
    • http://www.gorillawalker.com/dark-woods-kindle-edition.pdf
    • http://www.gorillawalker.com/water-sports-kids-guides-kindle-edition.pdf
    • http://www.gorillawalker.com/valtrex-valacyclovir-treats-herpes-virus-infections-including-shingles-cold-sores.pdf
    • http://www.gorillawalker.com/jung-s-theory-of-personality-a-modern-reappraisal-research-in.pdf
    • http://www.gorillawalker.com/a-man-for-all-seasons-a-drama-in-two-acts.pdf
    • http://www.gorillawalker.com/flavours-of-mexico-flavours-of-the-world.pdf
    • http://www.gorillawalker.com/killer-twins.pdf
    • http://www.gorillawalker.com/experiencing-the-passion-of-jesus-a-discussion-guide-on-history.pdf
    • http://www.gorillawalker.com/the-whizzkid-s-handbook-no-3.pdf
    • http://www.gorillawalker.com/rome-art-architecture.pdf
    • http://www.gorillawalker.com/cooking-down-east.pdf
    • http://www.gorillawalker.com/allgemeine-naturgeschichte-und-theorie-des-himmels.pdf
    • http://www.gorillawalker.com/prince.pdf
    • http://www.gorillawalker.com/a-history-of-secret-societies.pdf
    • http://www.gorillawalker.com/news-public-relations-and-power-the-media-in-focus-series.pdf
    • http://www.gorillawalker.com/things-that-fly-explainers.pdf
    • http://www.gorillawalker.com/sam-xp-3-0-high-school-site-license-for-more.pdf
    • http://www.gorillawalker.com/ethnobotany-survey-of-ethnobotanical-remedies-use-in-southern-punjab-pakistan.pdf
    • http://www.gorillawalker.com/information-technology-solutions-for-healthcare-health-informatics.pdf
    • http://www.gorillawalker.com/i-love-new-york-ingredients-and-recipes-kindle-edition.pdf
    • http://www.gorillawalker.com/ancient-worlds-modern-beads-30-stunning-beadwork-designs-inspired-by.pdf
    • http://www.gorillawalker.com/decision-making-in-neurocritical-care.pdf
    • http://www.gorillawalker.com/la-puesta-en-escena-en-latinoamerica-teoria-y-practica-teatral.pdf
    • http://www.gorillawalker.com/practical-jaguar-ownership-how-to-extend-the-life-of-a.pdf
    • http://www.gorillawalker.com/my-cousin-has-a-broken-heart.pdf
    • http://www.gorillawalker.com/the-house-of-war-and-witness.pdf
    • http://www.gorillawalker.com/introduction-to-realistic-philosophy-editiones-scholasticae.pdf
    • http://www.gorillawalker.com/forever-betrothed-never-the-bride-scandalous-seasons-book-1-kindle.pdf
    • http://www.gorillawalker.com/kobe-bryant-champion-basketball-star-sports-star-champions-kindle-edition.pdf
    • http://www.gorillawalker.com/to-laughter-with-questions-poetry-by-shelley-berman.pdf
    • http://www.gorillawalker.com/nelson-phil.pdf
    • http://www.gorillawalker.com/wicked-wise-how-to-solve-the-world-s-toughest-problems.pdf
    • http://www.gorillawalker.com/a-single-shot.pdf
    • http://www.gorillawalker.com/less-than-nations-central-eastern-european-minorities-after-wwi.pdf
    • http://www.gorillawalker.com/phtls-prehospital-trauma-life-support-7th-seventh-edition.pdf
    • http://www.gorillawalker.com/travel-with-william-tyndale-england-s-greatest-bible-translator-day.pdf
    • http://www.gorillawalker.com/social-security-legislation-2009-2010-v-4-tax-credits-and.pdf
    • http://www.gorillawalker.com/sugar-rush-disney-wreck-it-ralph-pictureback-r.pdf
    • http://www.gorillawalker.com/the-children-of-buchenwald-child-survivors-and-their-post-war.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/