Malicious PDF — malware analysis report

Static analysis result for SHA-256 8999a1c9ef9bc1f6…

MALICIOUS

PDF

3.3 KB
MD5: 655535ab769ee3d9a559eeaaa095d03e SHA-1: 53bdac665031a33e3810bc04cc6b5517f25482a4 SHA-256: 8999a1c9ef9bc1f62f99fe7aad29f6334fe7b834f6c05591ee001658bdb68a86
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript that is executed upon opening. This script appears to extract characters from the document's title property, likely to construct a malicious URL or command. The script then calls a function that executes the constructed string, indicating an attempt to download and run a second-stage payload. The ML classifier and ClamAV detection strongly support this malicious behavior.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
d1603084d31a388a6744f73e16a56fad74ee31e0e7e49dfa0e6d49e146fdc26f
pdf-javascript-stream PDF /JS object 7 at offset 0xA83 305 bytes