Malicious PDF — malware analysis report

Static analysis result for SHA-256 11f5dbc516e82a6b…

MALICIOUS

PDF

96.1 KB
MD5: 76421789b00d45667b49e49659412c31 SHA-1: acf5e95eb5741103f4d32de10e567423fb36531a SHA-256: 11f5dbc516e82a6bf64a853e0a6e3e691f607f2170cc5c4647cda7b0adcd1b7d
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file was flagged as malicious by a machine learning classifier and ClamAV, indicating it contains an exploit. The presence of JavaScript actions and embedded JS streams suggests the file attempts to execute malicious code, likely for initial client execution. The specific exploit and its payload are not detailed in the provided evidence, but the overall pattern points to a malicious document delivered via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36388 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36388
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.