Malicious PDF — malware analysis report

Static analysis result for SHA-256 0c4e062ee7ee3461…

MALICIOUS

PDF

27.6 KB
MD5: 4becac5f00dbe5ee3fd4944fe62cb33d SHA-1: c6a18130b1d61294b6d28ec3bc8e8800ab167c48 SHA-256: 0c4e062ee7ee3461b53102d5434440b1ed77ae228d080a7820088432e7a38ee6
166 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript, flagged by multiple heuristics and identified by ClamAV as Win.Trojan.Agent-36100. The JavaScript code appears to be heavily obfuscated but is designed to execute, likely to download and run a secondary payload. The ML classifier strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36100 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36100
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
a54e79489e6dd3c100efee4fc025025c6ff8dea87b668f76f766c85281db5e59
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 27477 bytes
Detection
ClamAV: Win.Trojan.Agent-36100
Obfuscation or payload: unlikely
javascript_obj0008_001.js
20f110acf14d8c9844b1a418edf0a6cceb6bba89caffca1b27a7352093d523b7
pdf-javascript-stream PDF /JS object 8 at offset 0x20A 27727 bytes
Detection
ClamAV: Win.Trojan.Agent-36100
Obfuscation or payload: unlikely
legacy_pdfkit_stage_000.js
5ae6c4f390c4bc4338e558d9cbc971054bc004472324a34405986e945afdc458
deobfuscated-js double percent-decoded annotation JavaScript at offset 0x1E7 15117 bytes