Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d15c71c6287b4fa…

MALICIOUS

PDF

45.0 KB
MD5: 0f3f83d9555342d533416d559a5f5a0a SHA-1: 2c344bbb4060b6eeb04fc048e148fcefba810d51 SHA-256: 7d15c71c6287b4faf0abf09fd97a106ab4c3fae2edf5e93cc06bdfac0e99e7e5
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious Link

The PDF file was detected as malicious by ClamAV with the signature Pdf.Exploit.Agent-36128. Static analysis revealed embedded JavaScript, indicating an attempt to exploit a vulnerability within the PDF reader. The JavaScript is likely responsible for downloading and executing a second-stage payload. The exact nature of the exploit and payload could not be fully determined due to the complexity and potential obfuscation of the embedded scripts.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36128 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36128
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
79a5ea3755cd6807bf42022c2288a44acd67b7c544e2837655c8a2620b83051a
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 45305 bytes
legacy_pdfkit_stage_000.js
26d3663bf5a40ee8eca1d156529829e4bdcd88f44e7da246ef2ae6e1864b3bd3
deobfuscated-js double percent-decoded annotation JavaScript at offset 0x1E7 33047 bytes