Malicious PDF — malware analysis report

Static analysis result for SHA-256 5421d7ae3a903f65…

MALICIOUS

PDF

27.8 KB
MD5: f5622fa155d2ab0eb4016ed8834073ae SHA-1: d71953877627e7b9eb62aa73a826532c3582c87d SHA-256: 5421d7ae3a903f65f25d215aa1ddbb3a875d16c9ddc9316e79249014ca55e333
166 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged as malicious by multiple heuristics, including a high-confidence ML classifier and ClamAV detection identifying it as Win.Trojan.Agent-36100. Embedded JavaScript streams were extracted, indicating the likely execution of malicious code. The ML classifier's high score and the ClamAV detection strongly suggest this PDF is designed to deliver a malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36100 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36100
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
69e6f16931f58b20e8efe1d7708e27f23ba85dd2b2ce724a49366d89a643fbfd
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 27717 bytes
Detection
ClamAV: Win.Trojan.Agent-36100
Obfuscation or payload: unlikely
legacy_pdfkit_stage_000.js
36cbef56b5bcb79d423a8ff2a0ed38f02353d33ab8fbbaf6acba1039daeb7c1b
deobfuscated-js double percent-decoded annotation JavaScript at offset 0x1E7 15237 bytes