Malicious PDF — malware analysis report

Static analysis result for SHA-256 34d798d0421ae0ad…

MALICIOUS

PDF

35.1 KB Created: 2012-08-14 23:36:43 +04:00 Authoring application: Adobe Acrobat 7.0 (via Adobe Acrobat 7.0 Image Conversion Plug-in)
MD5: 4d2811c0cd94ed5dc873ce4b1071656c SHA-1: 9764160106cbf7b5ddce5b80d17ededbd8030056 SHA-256: 34d798d0421ae0adf5482b17b1f4fe39eae42ae53c2e11a7b7ff2c1967e463f3
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The file is a PDF document identified by ClamAV as 'Pdf.Dropper.Agent-7247921-0'. Static analysis detected embedded JavaScript, indicating the document is designed to execute malicious code. The JavaScript's likely purpose is to download and execute a second-stage payload, which is a common dropper behavior. No specific family could be confidently identified.

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7247921-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7247921-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0106_000.js
cbf2059e89042fc4cff6911f5238d40a0fa0fc8a9c1441d111f15367f27dfd40
pdf-javascript-stream PDF /JS object 106 at offset 0x884B 1910 bytes