Malicious PDF — malware analysis report

Static analysis result for SHA-256 002e0edcb98a854c…

MALICIOUS

PDF

14.5 KB Created: 2009-11-15 19:41:70 Authoring application: PDF Library 4.3.9 (via PDF Library 3.9.7)
MD5: 1e79d75c2312529c8457fb958fe5fef4 SHA-1: 37fcca2cc215678f609b4e041b94fe5ae7597623 SHA-256: 002e0edcb98a854c1f32785e8219c79da8207423b07958e75a962ff866cc3e82
166 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File T1566.002 Spearphishing Attachment

The PDF file was flagged by multiple heuristics, including ML classification and ClamAV, indicating malicious intent. The embedded JavaScript, though obfuscated, likely attempts to download and execute a secondary payload, as suggested by the 'Pdf.Exploit.Agent-18227' and 'Win.Trojan.Agent-36166' ClamAV detections. The primary attack vector appears to be exploiting PDF vulnerabilities to deliver further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-18227 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-18227
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
b288f2a9ae9778edba6f308f0ca189460d2483f76b266b6c3f8781ccb4cd0376
pdf-javascript-stream PDF /JS object 7 at offset 0x1A5 74766 bytes
Detection
ClamAV: Win.Trojan.Agent-36166
Obfuscation or payload: unlikely