Malicious PDF — malware analysis report

Static analysis result for SHA-256 489cfe36bd2cc8bd…

MALICIOUS

PDF

3.3 KB
MD5: 2420e44870102b13d93b724b333fe7c9 SHA-1: a626b0fc254216cf19485cb2a5e37adf939f0528 SHA-256: 489cfe36bd2cc8bd5543a296a2704307d4ac92e354f3ca7e9cba88dda35d7823
108 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

This PDF file was flagged as malicious by ClamAV and a machine learning classifier. It contains embedded JavaScript, which is often used to exploit vulnerabilities within PDF readers. The JavaScript action and embedded JS stream heuristics indicate that the script is likely intended to download and execute a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
d1ef4a99dc920c5b548241f9ff54a0a8c37311043f481561bf65d8aa0539e7e9
pdf-javascript-stream PDF /JS object 7 at offset 0xA87 387 bytes