Malicious PDF — malware analysis report

Static analysis result for SHA-256 29772b257d6e1532…

MALICIOUS

PDF

12.8 KB
MD5: 5305f3a579dba10d8d41eee04094b2bb SHA-1: afd6cfff368a2543f0f2119339203bdd97793ae9 SHA-256: 29772b257d6e1532cf82aa9a12dcbd654ccd1b242d0a1060b04ed52cac1475b7
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is identified as a malicious PDF by ClamAV with the signature Pdf.Exploit.Agent-22103. Static analysis revealed embedded JavaScript, indicating an attempt to execute code. The JavaScript action and embedded JS stream heuristics confirm the presence of executable content within the PDF. The primary function of the embedded script is likely to download and execute a second-stage payload.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-22103 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-22103
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0020_000.js
af701efb1d43e0e8e5a6fa3dd7d2c71a63a43ed738a784db928607d66182d301
pdf-javascript-stream PDF /JS object 20 at offset 0x2D24 1206 bytes