Malicious PDF — malware analysis report

Static analysis result for SHA-256 79d2e28c44297c0d…

MALICIOUS

PDF

25.1 KB
MD5: fb3eaa92d5f538e0191a5953c5504558 SHA-1: e87df3f7808a98c7d2067e76258036326376efa4 SHA-256: 79d2e28c44297c0dc0218f87be29225408549d95ba505778bf849a7a8fe3e200
106 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 JavaScript

The PDF file contains embedded JavaScript, indicating an attempt to exploit vulnerabilities within the PDF reader. The ML classifier and ClamAV detection strongly suggest malicious intent, likely to execute arbitrary code on the victim's system. The presence of JavaScript points to the exploitation of client-side vulnerabilities.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36388 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36388
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.