Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e5337946e05cde9…

MALICIOUS

PDF

14.3 KB Created: 2009-11-15 19:41:70 Authoring application: PDF Library 4.3.9 (via PDF Library 3.9.7)
MD5: a1c8c759a5031d61408e01f9765a70a8 SHA-1: de718f86112adfb87327d9d87ec9b7a4f4803605 SHA-256: 0e5337946e05cde954236f33583078f5b76d06f26e1c8db3e9102d4f4e900e9a
166 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF contains embedded JavaScript, flagged by multiple heuristics, and is identified as malicious by ML classifiers and ClamAV. The JavaScript appears to be obfuscated but is designed to download and execute a secondary payload, indicated by the 'ML_NYX_PDF_MALICIOUS' and 'EXTRACTED_FILE_CLAMAV' firings. The presence of JavaScript in a PDF strongly suggests an attempt to exploit vulnerabilities for client execution, likely delivered via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36166 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36166
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
6aed552fe11e12280243186457ecdd7de8903b3b5c0923fbfdaff18ed1b29f42
pdf-javascript-stream PDF /JS object 7 at offset 0x1A5 74223 bytes
Detection
ClamAV: Win.Trojan.Agent-36166
Obfuscation or payload: unlikely