Malicious PDF — malware analysis report

Static analysis result for SHA-256 355c27cef811c4d2…

MALICIOUS

PDF

77.3 KB Created: 2009-08-26 23:02:49 Authoring application: Scribus 1.3.3.13 (via Scribus PDF Library 1.3.3.13)
MD5: 5b01e3de0bbce97eea0896fd89e00a60 SHA-1: 11cf0b7e43ab8245c19951795f538d5663d47eb4 SHA-256: 355c27cef811c4d259751e2a0924a14f3d08be09d7e3213894c8707e9e8e96ca
116 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The PDF contains multiple embedded JavaScript streams, with one stream being particularly large and heavily obfuscated. Heuristics and ML classification indicate malicious intent, and ClamAV identifies it as a known dropper. The JavaScript likely downloads and executes a second-stage payload, a common technique for malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8846

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7417865-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7417865-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0087_000.js
47a5835193a7c2a5617505f6240e07d9a1d01e9772beb0972dd21865628041fd
pdf-javascript-stream PDF /JS object 87 at offset 0xF22C 23692 bytes
javascript_obj0088_001.js
3d8b1723c9ade390c55341570e3e8fda2a7c4b00ad038f6db96eb4f75cf84904
pdf-javascript-stream PDF /JS object 88 at offset 0x128AF 222 bytes
javascript_obj0089_002.js
fc791c5e473cc1ae7b17bb45efc346ed6f45b4ef2dd6bb19d21453aba54c2566
pdf-javascript-stream PDF /JS object 89 at offset 0x129AE 224 bytes
javascript_obj0090_003.js
b56b30d0148454c230c55350badc251a32818b1a6ba37b418306742cdf68bdad
pdf-javascript-stream PDF /JS object 90 at offset 0x12A8F 172 bytes