Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a3073f354a4d602…

MALICIOUS

PDF

50.2 KB Created: 2009-11-06 21:43:10 +03:00 Authoring application: moreThose (via e7ba053d8ba932b77348b3987ea0e40b)
MD5: 85734bffa076cf3bf658b86708248a09 SHA-1: c0c773e0a28ad940693714d85317759c9bb9843b SHA-256: 8a3073f354a4d602e446c26e885140e35bf49d8d2a3c4d72531a269244408978
124 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The critical ClamAV detection 'Pdf.Exploit.Agent-2893' and the presence of embedded JavaScript with an eval() call strongly indicate malicious intent. The JavaScript is likely used to exploit a vulnerability within the PDF reader, leading to the execution of arbitrary code. The exact payload or exploit mechanism is not fully discernible due to obfuscation, but the overall pattern suggests a downloader or exploit delivery mechanism.

Heuristics 5

  • ClamAV: Pdf.Exploit.Agent-2893 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-2893
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0023_000.js
ecdcfb36fe2cf3b3faae9121d9cae6ed094ca9b2cf908a6cb6f82b44b2477a21
pdf-javascript-stream PDF /JS object 23 at offset 0x3232 4096 bytes
javascript_obj0024_001.js
97c1582f592f63143a1ce53263d0b37ae8a818643b1fe2430b7479cfcf4e4948
pdf-javascript-stream PDF /JS object 24 at offset 0xC20F 40 bytes