Malicious PDF — malware analysis report

Static analysis result for SHA-256 00182c2e1afecf39…

MALICIOUS

PDF

14.4 KB Created: 2009-11-15 19:41:70 Authoring application: PDF Library 4.3.9 (via PDF Library 3.9.7)
MD5: b7b2556a148da1c4a3a448e0c6fe794d SHA-1: 62640e95faf8d35dfcaf04cec0eb03cc49e1d653 SHA-256: 00182c2e1afecf39299a7019a8dca67018ee418dcc388d5dc7cfa01235b62812
166 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was flagged as malicious by multiple heuristics, including a critical ClamAV detection for 'Win.Trojan.Agent-36166'. It contains embedded JavaScript, which is often used to download and execute further malicious content. The JavaScript itself appears to be obfuscated, but its presence and the critical heuristic firings strongly indicate a downloader or agent-type malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36166 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36166
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
adfe0d827b0cff3808569065154aa951c495c32446868f2295611d158ec33c28
pdf-javascript-stream PDF /JS object 7 at offset 0x1A5 74333 bytes
Detection
ClamAV: Win.Trojan.Agent-36166
Obfuscation or payload: unlikely