Malicious PDF — malware analysis report

Static analysis result for SHA-256 37df396ef3a00a25…

MALICIOUS

PDF

12.4 KB
MD5: b758ef781b93a1e8a780833bd49c2b50 SHA-1: a4a1890e4956a9d71632cf6982779f7fba9c7258 SHA-256: 37df396ef3a00a25c977bfd7564421077e485c41e9fd1f2d1199024d880af90b
166 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious File

The PDF contains embedded JavaScript, indicated by multiple heuristic firings and the presence of an extracted JavaScript file. The ML classifier and ClamAV detections strongly suggest malicious intent, likely involving the execution of an exploit. The embedded JavaScript is the primary mechanism for delivering the malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-36365 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36365
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
12fe3c61533e553f0ca537c543333af0d7ea2fb8bc6ba4bd8ad89d9f2fcdd002
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11566 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36364
Obfuscation or payload: unlikely