Malicious PDF — malware analysis report

Static analysis result for SHA-256 3209d43a32121c21…

MALICIOUS

PDF

12.4 KB
MD5: 93809f35335763e4de5e1868a5d7b370 SHA-1: 41bab255e2dbe029ffebe3477c9f7e7553796c13 SHA-256: 3209d43a32121c21d6fd06337cca1326b22002a706cc750fdf2d1e2f73ad9729
76 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The sample is a PDF file flagged by ClamAV as Pdf.Exploit.Agent-36723. Static analysis identified embedded JavaScript, indicating an attempt to exploit a PDF vulnerability. The embedded JavaScript stream is likely responsible for downloading and executing a secondary payload, which is a common technique for initial access.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36723 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36723
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
6a0e541a107323d3d4330a2fc8095fd291e9bde9a3bda49724bf740c5bf45d82
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11585 bytes