Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ee012f50ba7e46b…

MALICIOUS

PDF

10.3 KB
MD5: 38c21e05c1620ab4a2bddb3996df9110 SHA-1: 4d56ccff4af941131ef0d74f60abf4021322bf95 SHA-256: 7ee012f50ba7e46b068adab9ca673e5e54c899ae245b0e38425b85d7edab87d8
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript T1204.002 Malicious File

The PDF file was flagged by ClamAV as 'Pdf.Exploit.Agent-35646' and a machine learning classifier indicated a high probability of maliciousness. Heuristics indicate the presence of embedded JavaScript, which is often used to exploit vulnerabilities or download further malicious content. The embedded JavaScript stream is the primary mechanism for this attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9883

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-35646 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-35646
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objstm_0005_00.bin
f97ab2215b6de1832c20e16ffc20516165bb941e49feed837816a53c53f21b26
pdf-objstm-decoded PDF /ObjStm 5 0 obj (inflated) 99 bytes
font_00_cff_off000007fe.bin
f2306d0a5e670cbada5a60316e1d4255002bdd01e05209cef398fe1a1be49b23
pdf-font-stream PDF embedded font (cff) at offset 0x7FE 733 bytes