Malicious PDF — malware analysis report

Static analysis result for SHA-256 11c1b490918b09fd…

MALICIOUS

PDF

77.3 KB Created: 2009-08-26 23:02:49 Authoring application: Scribus 1.3.3.13 (via Scribus PDF Library 1.3.3.13)
MD5: 3fa31de1418605dfcfad4f99dda137be SHA-1: 2dbed2124f421ff47d915416dc9f8361f4580df4 SHA-256: 11c1b490918b09fd07a2a0f06d487e4b3554f2e9387d5b0784b18db5e3090f7e
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The PDF contains embedded JavaScript, flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Dropper.Agent-7230520-0'. The JavaScript appears to be obfuscated but is designed to download and execute a secondary payload, a common technique for malware droppers. The primary attack pattern is likely spearphishing attachment, with the JavaScript acting as the execution mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8846

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7230520-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7230520-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0087_000.js
77689440bf7df6a5fcd6349327d2128c6cb1f4106ac3f1a985d89cad1a167515
pdf-javascript-stream PDF /JS object 87 at offset 0xF22C 23609 bytes
javascript_obj0088_001.js
29ceacbae847dcd89510f7ff0e6519e55d927bbc350e539970738b8da7a75343
pdf-javascript-stream PDF /JS object 88 at offset 0x128A4 212 bytes
javascript_obj0089_002.js
fa112fb292d3c180168484f084b8d6e3e87d6074f1ff99b5d3cc6b97f67d8c83
pdf-javascript-stream PDF /JS object 89 at offset 0x1299A 175 bytes
javascript_obj0090_003.js
f8bee4253c58ea81fb5acad6c6791b46e8622c56127c73e0c9fef5bad0b7991a
pdf-javascript-stream PDF /JS object 90 at offset 0x12A6E 169 bytes