Malicious PDF — malware analysis report

Static analysis result for SHA-256 582d8fc6d8a91324…

MALICIOUS

PDF

37.0 KB Created: 2010-04-19 21:56:31 +04:00 Authoring application: TCPDF (via TCPDF 4.8.032 (http://www.tcpdf.org))
MD5: 262846c225ea79f081e9f60c14a61311 SHA-1: b80805b7379086f9a9f19477becd9a6d5b09c919 SHA-256: 582d8fc6d8a913244c7e89592e0dd263818368fd6a98fe03c2300a41a26ea632
84 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

The critical ClamAV detection of 'Pdf.Exploit.Agent-23546' strongly indicates malicious intent. The presence of embedded JavaScript, triggered by optional content groups and direct actions, suggests the PDF is designed to exploit vulnerabilities and execute arbitrary code. The embedded JavaScript is likely responsible for downloading and executing a second-stage payload, though its exact function is obscured by obfuscation.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-23546 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-23546
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0010_000.js
dffb6510801cc87aff72ee80ed3d5ab8d86baee21c911d9bd780750e28aa1d21
pdf-javascript-stream PDF /JS object 10 at offset 0x89AB 1344 bytes