Malicious PDF — malware analysis report

Static analysis result for SHA-256 43388fd5cb92c262…

MALICIOUS

PDF

19.8 KB
MD5: 777084d30babc34777c0ce5a17cdc40f SHA-1: 1bf866bdf0488b8fa253e3ae0f5aa4423b2978e4 SHA-256: 43388fd5cb92c262659595338af5a4c39ac05bfda37a7050c72af34c084a93d7
136 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings and the presence of a javascript_obj0008_000.js artifact. ClamAV detections (Pdf.Exploit.Agent-36307) confirm its malicious nature. The embedded JavaScript is likely responsible for exploiting a vulnerability within the PDF reader to achieve arbitrary code execution, leading to the download or execution of a secondary payload.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-36307 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36307
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
ad2d3acb2b4d1eac3e232cbd494e0e988203a95003728257b5814bacd3f6bb15
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 3193 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36307
Obfuscation or payload: unlikely