Pdf.Dropper.Agent-7263393-0 — PDF malware analysis

Static analysis result for SHA-256 5a9f14d7be383808…

MALICIOUS

PDF

58.0 KB Created: 2009-11-15 19:41:70 Authoring application: PDF Library 4.3.9 (via PDF Library 3.9.7)
MD5: 20d3a52a81d0b90bbd04789d545b3463 SHA-1: 197e8d098caae358b1238f1e7abffa0b2e7cafeb SHA-256: 5a9f14d7be383808d32d4f131dc1dd9a65daa9fce184d7ac168465e60bbe344a
108 Risk Score

Malware Insights

Pdf.Dropper.Agent-7263393-0 · confidence 95%

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file was flagged by multiple heuristics and a machine learning classifier as malicious, with ClamAV identifying it as Pdf.Dropper.Agent-7263393-0. The embedded JavaScript, while heavily obfuscated, is likely responsible for executing an exploit and downloading a secondary payload. The presence of JavaScript actions and embedded JS streams points to T1059.007 (JavaScript) and T1203 (Exploitation for Client Execution). Given the nature of dropper malware, it is highly probable that this file was delivered as a spearphishing attachment (T1566.001).

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7263393-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7263393-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PSEOF. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
9241589de69fa26c408111425871db311bdc012512ee31e11c328edafe5534f1
pdf-javascript-stream PDF /JS object 7 at offset 0x1A5 116677 bytes