Malicious PDF — malware analysis report

Static analysis result for SHA-256 84684d4a5c211a59…

MALICIOUS

PDF

27.7 KB
MD5: a843890e7dc794378f83d2cefb7d4587 SHA-1: 45fdd6f9ee701ba29dee35a24b6a10b9091d83a6 SHA-256: 84684d4a5c211a59bd935140f248ddc83022c94ca487f77383d7f88631487c57
166 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The PDF file was flagged as malicious by multiple heuristics, including ML classifiers and ClamAV, which identified it as Win.Trojan.Agent-36100. Embedded JavaScript streams were detected, indicating the likely execution of malicious code. The obfuscated JavaScript appears to be designed to download and execute a secondary payload, a common tactic for this type of threat.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36100 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36100
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
1c95f88319af91bfed3b75f02dc1c8b07409db490fc46132f99ef3d092c49c09
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 27621 bytes
Detection
ClamAV: Win.Trojan.Agent-36100
Obfuscation or payload: unlikely
javascript_obj0008_001.js
27ab92cf08ca831599384c924d7c677a0a9231d72ada2f29043e7084dd8024bd
pdf-javascript-stream PDF /JS object 8 at offset 0x20A 27871 bytes
Detection
ClamAV: Win.Trojan.Agent-36100
Obfuscation or payload: unlikely
legacy_pdfkit_stage_000.js
0760ecfb757d87b6bb613058b5521bd7a814270e5a2d824f6ac3465375ee7683
deobfuscated-js double percent-decoded annotation JavaScript at offset 0x1E7 15189 bytes