Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c8c84a10eb4afa1…

MALICIOUS

PDF

3.2 KB
MD5: 877e898202ecbffbd8f655157bd252a8 SHA-1: 06bacbccae51749c24e1b875db7055a294f24627 SHA-256: 3c8c84a10eb4afa1e3bc6a6b96e92e3e270b50eec7f59cdca3afe3d9ad3870e9
76 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious File

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. This JavaScript is likely used to exploit a vulnerability within the PDF reader, leading to the execution of malicious code. The ClamAV detection further confirms its malicious nature. The specific exploit and its payload are not detailed in the provided evidence, but the general pattern suggests an attempt to compromise the user's system via a malicious PDF.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
4354ff0cff673f5b5022f9d37e21511d6f0a19e9f70d43ead6b849a53dd1f51c
pdf-javascript-stream PDF /JS object 7 at offset 0x9C5 529 bytes