Malicious PDF — malware analysis report

Static analysis result for SHA-256 899b6127f7b7a5fb…

MALICIOUS

PDF

33.5 KB
MD5: f79bf59ae5d9bba6118e6d989b010139 SHA-1: 991a9abc3ded763b71826edf28dc43e752045b00 SHA-256: 899b6127f7b7a5fb6234474fbca917165e6f98f4da676a8163f9e6840bfd43ce
106 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link

The file is identified as a malicious PDF by ClamAV and a machine learning classifier. Heuristics indicate the presence of embedded JavaScript, suggesting an attempt to exploit vulnerabilities within the PDF reader to execute malicious code. The specific exploit and payload delivery mechanism are not detailed, but the presence of JavaScript points towards an exploit execution attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36388 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36388
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.