Malicious PDF / .PHP — malware analysis report

Static analysis result for SHA-256 28e8acd5495b2e77…

MALICIOUS

PDF / .PHP

14.3 KB Created: 2010-03-19 20:57:58 Authoring application: Cekxehitqeniji (via Fopabisavafhelaxofino)
MD5: 5ca9251ec5381a6fd577437bacaecf35 SHA-1: 32acc6d01f96ce6e31ecb5b1fd6d54c6849840a9 SHA-256: 28e8acd5495b2e770e5558b182972d69ba99f546adf257c571e96a8207fafd0a
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The sample is identified as malicious by ClamAV with the signature Pdf.Exploit.Agent-20453. Static analysis detected embedded JavaScript, indicating an attempt to exploit a PDF vulnerability. The document body contains seemingly random text, suggesting it is not intended for human consumption and likely serves as a lure or obfuscation. The presence of JavaScript actions and streams strongly suggests the execution of malicious code.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-20453 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-20453
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0018_000.js
5b6d12cb26cdd8aac2bc5bac28b3153264ee9831dc62f81219b27dbe54146282
pdf-javascript-stream PDF /JS object 18 at offset 0x235E 2548928 bytes