Malicious PDF — malware analysis report

Static analysis result for SHA-256 3844e864be24f868…

MALICIOUS

PDF

3.3 KB
MD5: ebab1e7efac329dcb2dc1f29ba9f94a0 SHA-1: 9d8844a5f3f340d7d9c2e053842883c97a2a5dbb SHA-256: 3844e864be24f8685e0fc6cfa4c7fc775b67df214dc68f98f3fbc7f09d5494e3
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

This PDF file was flagged as malicious by ClamAV and a machine learning classifier. It contains embedded JavaScript, which is a common technique for exploiting PDF vulnerabilities to deliver malicious payloads. The JavaScript action at offset 0xF0 and the embedded JS stream at offset 0xFD indicate the execution of code. The ClamAV detection name 'Pdf.Exploit.Agent-36121' further supports its malicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
c24a4f9aa297abc2dacb692d795ab0eb4cc787c45c0ec37688b345818f1336b2
pdf-javascript-stream PDF /JS object 7 at offset 0xA87 332 bytes