Malicious PDF — malware analysis report

Static analysis result for SHA-256 092e402dfc380b47…

MALICIOUS

PDF

23.2 KB
MD5: 958254c3c1288ff71ae02a627d3e6f74 SHA-1: c3b3521f291f2b07e9d47dafde032e0c6b0a78cb SHA-256: 092e402dfc380b478620a613db59f16b233ee34bf1453f8594d6467b316f2e40
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The file is identified as malicious by ML classifiers and ClamAV, with heuristics indicating the presence of embedded JavaScript within a PDF object stream. This JavaScript is likely used to exploit a client execution vulnerability, enabling the download of further malicious content. No specific family could be identified, and no direct IOCs like URLs or hashes were extracted from the provided evidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9981

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-35646 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-35646
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objstm_0019_00.bin
729414f6718edf0ec69ca74ac4aadd8cf5d728dc183704dd6bc7f97d97bd8911
pdf-objstm-decoded PDF /ObjStm 19 0 obj (inflated) 270 bytes