Malicious PDF — malware analysis report

Static analysis result for SHA-256 3fd8635e72ee0475…

MALICIOUS

PDF

7.7 KB Created: 2009-06-14 15:57:38 Authoring application: Ividrebou
MD5: 8261de166377adcbe461f1b059749618 SHA-1: aaf8568c8f8ca78a5b09727bb7a5a8d4f148b91a SHA-256: 3fd8635e72ee0475cc46677c3e21ac48a14c8d141906c912e1fc020c6e647cb5
158 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1059.007 JavaScript

The sample is a PDF file that contains embedded JavaScript. Heuristics indicate the use of `eval()` and `unescape()` functions, suggesting obfuscated code execution. The ClamAV detection `Pdf.Exploit.Agent-35649` further confirms its malicious nature. The embedded JavaScript, named `javascript_obj0007_000.js`, is likely responsible for exploiting a PDF vulnerability to download and execute a second-stage payload.

Heuristics 6

  • ClamAV: Pdf.Exploit.Agent-35649 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-35649
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
f65f48ee11b1235f7951209f15ec3a30210f006b8b2ec5c4ce13876cf01c2bcb
pdf-javascript-stream PDF /JS object 7 at offset 0x358 6550 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 11 eval/decoder/string-building token(s).