Malicious PDF — malware analysis report

Static analysis result for SHA-256 47826b34ea87e0fa…

MALICIOUS

PDF

12.3 KB
MD5: 6c51ef07ebc20562e923cda23dd13a55 SHA-1: bcffaf614a13a64b6f24bf089bfad9e49d677bac SHA-256: 47826b34ea87e0fa4dc298995ee86c849c3ac3ffe7ffaff1402344f8ad055839
76 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1204.002 Malicious File: User Execution: Malicious PDF

The file is identified as a malicious PDF by ClamAV with the signature Pdf.Exploit.Agent-36723. Static analysis detected embedded JavaScript, indicating an attempt to execute malicious code upon opening the PDF. The presence of JavaScript actions and streams strongly suggests the PDF is designed to exploit vulnerabilities and download or execute a secondary payload.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36723 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36723
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
aa4388056434fc5ad8639bf345f3085163662ebf3730c6557cd3403bc1589cf7
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11469 bytes