Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d5d56c5014e6870…

MALICIOUS

PDF

3.2 KB
MD5: a71e2cc44856af2e6a4c8e254f728a98 SHA-1: 299d3010e5cdb25f5c420fa55d50b18a0ec95522 SHA-256: 2d5d56c5014e6870fbc2cc509b344ece235b624fdfcd6664205342e23d801266
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by the 'PDF_JAVASCRIPT' and 'PDF_JS' heuristics. ClamAV detection 'Pdf.Exploit.Agent-36121' confirms its malicious nature. The embedded JavaScript is likely responsible for exploiting a vulnerability within the PDF reader to execute arbitrary code, although the specific action is not detailed in the provided evidence.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
b72890b724b8834104000315a0a4fc80e227a32b24284eeef4bf0d4d992c7be8
pdf-javascript-stream PDF /JS object 7 at offset 0x9C8 473 bytes