Malicious PDF — malware analysis report

Static analysis result for SHA-256 1c03c7704bc997c4…

MALICIOUS

PDF

45.0 KB
MD5: f82f555ff2e041ee3ea74cafef7cd34b SHA-1: 12ab0fdb343192e1be174a668d7f0da0f557834c SHA-256: 1c03c7704bc997c482c65f5be13ad0dc91afc70049a187d4edf7669d32cf706e
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The file is identified as a malicious PDF by ClamAV and a machine learning classifier. Embedded JavaScript, detected by heuristics, is likely responsible for executing an exploit. The ML classifier's high confidence score and the ClamAV detection strongly indicate malicious intent, likely involving the exploitation of a PDF vulnerability to deliver a payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36128 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36128
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
b8723e12e084e6869872013bbf5be29562b5abffc72390d188c7061822312196
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 45305 bytes
legacy_pdfkit_stage_000.js
6bf03d9f04637ec17d269bb751a3743fb78020cf7d1801a7d7881e661fd707f5
deobfuscated-js double percent-decoded annotation JavaScript at offset 0x1E7 33047 bytes