Malicious PDF — malware analysis report

Static analysis result for SHA-256 57a46b8106675b91…

MALICIOUS

PDF

46.9 KB Created: 2009-12-02 17:42:45 +03:00 Authoring application: sLong (via 41ccc97e4f1b5de999aa6468ff787d89)
MD5: 491b62d9eb4bf2b3e6977b7d960889b6 SHA-1: 122f52eb35e56b4570a5bce69149ba5fe3858d8b SHA-256: 57a46b8106675b915c5cb4fb7b316fb2fc5ff9959d4686c61e9c1772b2b3659f
124 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The critical ClamAV detection for 'Pdf.Dropper.Agent-1828752' strongly indicates malicious intent. The presence of PDF JavaScript actions, embedded JS streams, and a high-confidence eval() call point to the execution of obfuscated code. This script likely downloads and executes a second-stage payload, a common dropper behavior. The document body is heavily obfuscated and does not provide direct clues to the user-facing lure.

Heuristics 5

  • ClamAV: Pdf.Dropper.Agent-1828752 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-1828752
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0017_000.js
a7fccea0b6c1bf6b461333113a8e70d5b3ae2566131b75d7b07eb9c62536d4d0
pdf-javascript-stream PDF /JS object 17 at offset 0x27EF 4096 bytes
javascript_obj0018_001.js
8c5d6049e5b76dcde2a0c4b6629fed96b9367a215311eff523ea49928276adcc
pdf-javascript-stream PDF /JS object 18 at offset 0xB53C 42 bytes