Malicious PDF — malware analysis report

Static analysis result for SHA-256 5483fe1e0fd6ef4a…

MALICIOUS

PDF

37.8 KB Created: 2010-04-19 21:57:07 +04:00 Authoring application: TCPDF (via TCPDF 4.8.032 (http://www.tcpdf.org))
MD5: b4296c148fc69046c44630be289962fc SHA-1: d5c4438133494925fa14790e961b80e13fda2b06 SHA-256: 5483fe1e0fd6ef4af983d0280d1947de302f95a07659d9bc7060c6360369cff4
84 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings related to PDF JavaScript actions and streams. The ClamAV detection 'Pdf.Exploit.Agent-23584' strongly suggests this is a known exploit. The embedded JavaScript is likely responsible for triggering the exploit, leading to the execution of malicious code. No specific URLs or hashes were extracted, limiting further IOC identification.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-23584 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-23584
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0010_000.js
c67310a169d87449e0a526a4510a8b73467f303f3853c5a754c9dce9f52d3e01
pdf-javascript-stream PDF /JS object 10 at offset 0x8D00 1346 bytes