Malicious PDF — malware analysis report

Static analysis result for SHA-256 4407d3265dc0c82a…

MALICIOUS

PDF

5.2 KB Created: 2011-03-18 21:11:07 Authoring application: asp nom
MD5: 7bae46440969e921b9ebfee7733d5566 SHA-1: e4cafecc231114afe263e84922763b0ae32f1b04 SHA-256: 4407d3265dc0c82ac7b366405d6048cc558d87b141a4806788c46eec425f4be7
78 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The ClamAV detection 'Pdf.Dropper.Agent-7255489-0' strongly suggests this is a dropper. The extracted JavaScript file, 'javascript_obj0003_000.js', is likely responsible for downloading and executing a second-stage payload. The document body contains seemingly random text, which is common for obfuscated or decoy content in malicious documents.

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7255489-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7255489-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0003_000.js
4c30ac9ae0f522b9584dc24e29b23d4fb37fe7318ee410babceff5c67ae9f7fb
pdf-javascript-stream PDF /JS object 3 at offset 0x828 4285 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).