Malicious PDF — malware analysis report

Static analysis result for SHA-256 355c27cef811c4d2…

MALICIOUS

PDF

77.3 KB Created: 2009-08-26 23:02:49 Authoring application: Scribus 1.3.3.13 (via Scribus PDF Library 1.3.3.13)
MD5: 5b01e3de0bbce97eea0896fd89e00a60 SHA-1: 11cf0b7e43ab8245c19951795f538d5663d47eb4 SHA-256: 355c27cef811c4d259751e2a0924a14f3d08be09d7e3213894c8707e9e8e96ca
116 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Dropper.Agent-7417865-0' and an ML classifier indicating maliciousness. The presence of embedded JavaScript streams strongly suggests that the PDF is designed to execute malicious code, likely to download and run a secondary payload. The document body was unreadable, but the combination of PDF structure and JavaScript points to a dropper or downloader attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8846

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7417865-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7417865-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0087_000.js
47a5835193a7c2a5617505f6240e07d9a1d01e9772beb0972dd21865628041fd
pdf-javascript-stream PDF /JS object 87 at offset 0xF22C 23692 bytes
javascript_obj0088_001.js
3d8b1723c9ade390c55341570e3e8fda2a7c4b00ad038f6db96eb4f75cf84904
pdf-javascript-stream PDF /JS object 88 at offset 0x128AF 222 bytes
javascript_obj0089_002.js
fc791c5e473cc1ae7b17bb45efc346ed6f45b4ef2dd6bb19d21453aba54c2566
pdf-javascript-stream PDF /JS object 89 at offset 0x129AE 224 bytes
javascript_obj0090_003.js
b56b30d0148454c230c55350badc251a32818b1a6ba37b418306742cdf68bdad
pdf-javascript-stream PDF /JS object 90 at offset 0x12A8F 172 bytes