MALICIOUS
112
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 JavaScript
T1204.002 Malicious Link or Trusted Form
The PDF file contains embedded JavaScript streams and triggers JavaScript actions, indicating an attempt to exploit vulnerabilities. The ClamAV detection 'Pdf.Exploit.Agent-13584' strongly suggests malicious intent. The embedded JavaScript is likely responsible for executing a malicious payload, although its exact function cannot be determined due to obfuscation.
Heuristics 6
-
ClamAV: Pdf.Exploit.Agent-13584 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Exploit.Agent-13584
-
ASCIIHexDecode filter (with exploit indicators) medium PDF_FILTER_HEXHex-encoding filter present alongside exploit delivery indicators — often used to hide payload or shellcode bytes
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
-
Optional Content Group with action trigger low PDF_OPTIONAL_CONTENTOptional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0014_000.js71ae9e575b1757a389404b7eeaf169e496b9d5e2cab548536592a994cd0c2c05 |
pdf-javascript-stream | PDF /JS object 14 at offset 0x1B2F | 35681 bytes |
javascript_obj0016_001.js659e451c5fc339c067e5c2a37a02b752d66b5a4feb8fbf579e7d485dad76af95 |
pdf-javascript-stream | PDF /JS object 16 at offset 0x66E1 | 113 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.