Malicious PDF — malware analysis report

Static analysis result for SHA-256 6cb923a1af6abf5b…

MALICIOUS

PDF

3.3 KB
MD5: c3adcb30682f2643f0eb49df51fa2a3f SHA-1: a61b2439f4b8d731c59e3ca4cc1674a1ba30bd7b SHA-256: 6cb923a1af6abf5bc035e3debb5445f9d3dbc656d67c31cbfa9744241a66e115
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file was flagged as malicious by ML classifiers and ClamAV, indicating it contains an exploit. Embedded JavaScript is present, which is obfuscated but appears to decode a string from the PDF's title metadata. This decoded string is then executed, likely leading to the download and execution of a second-stage payload. The primary technique observed is the exploitation of a PDF vulnerability to run JavaScript.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
4429b6267d31a814f58e862bfd13721346d133d1e7f5cc1a5d6db0d2c74822d0
pdf-javascript-stream PDF /JS object 7 at offset 0xA88 349 bytes