Malicious PDF — malware analysis report

Static analysis result for SHA-256 e68968d443481252…

MALICIOUS

PDF

31.5 KB Created: 2020-01-16 21:31:44 +03:00 Authoring application: Word (via Mac OS X 10.7.5 Quartz PDFContext)
MD5: 512c8e0956a705238d6b4629ca73e006 SHA-1: d3aef94cb9d738087410ea8ba599d1d4e6096372 SHA-256: e68968d4434812521d70be049691149e9393ca036c30ba099f551814b7aaf816
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The ClamAV heuristic 'Pdf.Dropper.Agent-7567417-0' indicates this PDF is a dropper. The presence of numerous embedded URLs, such as 'http://www.gorillawalker.com/girl-studio-booklet-of-24-postcards.pdf', strongly suggests the document's purpose is to redirect the user to external resources, likely for further malware delivery. No scripts were extracted from this sample.

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7567417-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7567417-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gorillawalker.com/girl-studio-booklet-of-24-postcards.pdf
    • http://www.gorillawalker.com/precalculus-with-trigonometry.pdf
    • http://www.gorillawalker.com/let-sleeping-dogs-lie.pdf
    • http://www.gorillawalker.com/nelson-handwriting-developing-skills-book-3-bk-3.pdf
    • http://www.gorillawalker.com/system-des-transzendentalen-idealismus.pdf
    • http://www.gorillawalker.com/secrets-of-the-great-rainmakers-the-keys-to-success-and.pdf
    • http://www.gorillawalker.com/flash-cards-on-the-farm.pdf
    • http://www.gorillawalker.com/etsy-selling-learn-how-to-start-your-own-successful-etsy.pdf
    • http://www.gorillawalker.com/the-trashman-cometh.pdf
    • http://www.gorillawalker.com/seasons-the-syndicate-kindle-edition.pdf
    • http://www.gorillawalker.com/my-fellow-traveller.pdf
    • http://www.gorillawalker.com/how-to-start-your-own-law-practice-and-survive-the.pdf
    • http://www.gorillawalker.com/under-the-shadow-of-wings.pdf
    • http://www.gorillawalker.com/ethical-issues-in-sandplay-therapy-practice-and-research-springerbriefs-in.pdf
    • http://www.gorillawalker.com/the-age-of-the-dictators-a-study-of-the-european.pdf
    • http://www.gorillawalker.com/the-janacek-opera-libretti-translations-and-pronunciation-vol-1-prihody.pdf
    • http://www.gorillawalker.com/training-needs-assessment-methods-tools-and-techniques.pdf
    • http://www.gorillawalker.com/inkworks-darren-quach-sketchbook-vol-01.pdf
    • http://www.gorillawalker.com/lester-young-jazz-perspectives.pdf
    • http://www.gorillawalker.com/pediatric-physical-therapy.pdf
    • http://www.gorillawalker.com/goats-2016-square-12x12-multilingual-edition.pdf
    • http://www.gorillawalker.com/shadows-across-the-sahara-travels-with-camels-from-lake-chad.pdf
    • http://www.gorillawalker.com/sons-of-chaos-mc-biker-erotic-romance.pdf
    • http://www.gorillawalker.com/hot-air-frying-more.pdf
    • http://www.gorillawalker.com/componentes-del-desarrollo-motor-t.pdf
    • http://www.gorillawalker.com/lotta-makes-a-mess.pdf
    • http://www.gorillawalker.com/governing-prisons.pdf
    • http://www.gorillawalker.com/learn-french-in-7-days-the-ultimate-crash-course-to.pdf
    • http://www.gorillawalker.com/pocket-mechanic-for-volvo-360-carburettor-and-fuel-injection-1988.pdf
    • http://www.gorillawalker.com/white-zombie-anatomy-of-a-horror-film.pdf
    • http://www.gorillawalker.com/the-importance-of-being-earnest-a-trivial-comedy-for-serious.pdf
    • http://www.gorillawalker.com/zhangjiajie-map-in-english-and-south-korea.pdf
    • http://www.gorillawalker.com/vengeance-an-erotic-thriller.pdf
    • http://www.gorillawalker.com/gather-yourselves-together.pdf
    • http://www.gorillawalker.com/offshore-oil-and-gas-development-in-the-arctic-under-international.pdf
    • http://www.gorillawalker.com/oxford-a-z-of-grammar-and-punctuation.pdf
    • http://www.gorillawalker.com/soups-original-series.pdf
    • http://www.gorillawalker.com/a-practical-guide-to-interior-design-planning-a-home.pdf
    • http://www.gorillawalker.com/the-jesus-i-never-knew-kindle-edition.pdf
    • http://www.gorillawalker.com/sepsis-and-organ-dysfunction-epidemiology-and-scoring-systems-pathophysiology-and.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/id/