Malicious PDF — malware analysis report

Static analysis result for SHA-256 209548261d1a46e1…

MALICIOUS

PDF

45.0 KB
MD5: 2af90a9f16cfec81b52c05daa6e3107e SHA-1: 571fafcddeac29bac02375258ec4fa0b1f567386 SHA-256: 209548261d1a46e1539746d837edae903e875dcd635ce1756ad30d1e490166f1
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was detected by ClamAV as Pdf.Exploit.Agent-36128, indicating it contains an exploit. The presence of embedded JavaScript streams further supports this, as these are commonly used to deliver exploits within PDF documents. The JavaScript is heavily obfuscated, making it difficult to determine the exact payload, but the overall pattern suggests it's designed to download and execute a second-stage malicious file.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36128 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36128
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
2b14f4afea7b4fa6fb80f82eb16e44fbb824e6818092048d1236cd9fbe1be069
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 45305 bytes
legacy_pdfkit_stage_000.js
19a8888de79d721557cf02cdc694b0309dcfd5c4157449c8f1c3d2e281550284
deobfuscated-js double percent-decoded annotation JavaScript at offset 0x1E7 33047 bytes