Malicious PDF — malware analysis report

Static analysis result for SHA-256 5ca5f27992219e3f…

MALICIOUS

PDF

19.8 KB
MD5: c82ff8066b59427f7729029ce0606685 SHA-1: faa87ae011199dce66b79e55f74dd41a6fd0034c SHA-256: 5ca5f27992219e3f1ec7ba33738213da457579ccc448b8f3a0e91bfd98cfefe0
166 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The sample is a PDF file flagged as malicious by ClamAV and an ML classifier, indicating it contains an exploit. Embedded JavaScript streams were extracted, which are heavily obfuscated but appear to be designed to execute further code. The primary detection signature is Pdf.Exploit.Agent-36307, suggesting a known exploit targeting PDF viewers.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-36307 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36307
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
ec67b90a08c0b6b67a4b84e8bcf96f0f3b164eddee799364b52d899e3b97b057
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 3193 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36307
Obfuscation or payload: unlikely
javascript_obj0008_001.js
a571d53769f58150bbaf3d19bfd9d22d55ef1c63929cea7414758f809152219a
pdf-javascript-stream PDF /JS object 8 at offset 0x209 19785 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36307
Obfuscation or payload: unlikely