Malicious PDF — malware analysis report

Static analysis result for SHA-256 314b8ec70c7c8e8e…

MALICIOUS

PDF

3.3 KB
MD5: 6dd2ee0a365bcd2a868962ddc1b9f579 SHA-1: c5e5bb48da9bdab02c1abd726dc3082ae73ecc4e SHA-256: 314b8ec70c7c8e8e0b0757c58dbaa766a51970a8ec8032f141b5da50f89b2c70
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious Link

The PDF file was detected by ClamAV as Pdf.Exploit.Agent-36121, indicating it contains a known exploit. Heuristics indicate the presence of embedded JavaScript, which is likely used to deliver the exploit payload. The JavaScript action and embedded JS stream suggest the file attempts to execute malicious code upon opening.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
ff6497aed782933eb67edad141fa5a7e78cdc87c00a30d849b7cb549f765c4cc
pdf-javascript-stream PDF /JS object 7 at offset 0xA85 294 bytes