Malicious PDF — malware analysis report

Static analysis result for SHA-256 68852fbf5b626993…

MALICIOUS

PDF

14.5 KB Created: 2009-11-15 19:41:70 Authoring application: PDF Library 4.3.9 (via PDF Library 3.9.7)
MD5: 863c46aa2b62ad6da8e6fd9a3bf734f9 SHA-1: 9f34687eb724bc86da4fea40c4d67749485e4d3a SHA-256: 68852fbf5b626993dbb8453e7c1fabc71f70388416b88ab6adcd99b4661bcfa2
166 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of embedded JavaScript, identified by multiple heuristics, suggests an attempt to exploit vulnerabilities within the PDF reader to execute arbitrary code. The JavaScript itself appears to be heavily obfuscated, but its presence and the overall malicious verdict strongly indicate it's designed to download and execute a secondary payload, consistent with the 'Win.Trojan.Agent-36166' detection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36166 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36166
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
68475a55363cbe722018d0664c7f86cbabe3723c508ececae7d49b4c0575d383
pdf-javascript-stream PDF /JS object 7 at offset 0x1A5 74805 bytes
Detection
ClamAV: Win.Trojan.Agent-36166
Obfuscation or payload: unlikely