Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ab9a83f83cf9362…

MALICIOUS

PDF

10.8 KB
MD5: 18d594e4a1c8654d7e1c37a61bfff000 SHA-1: 104b642c8d344e7597c5badaa7096fe5b39e7e40 SHA-256: 8ab9a83f83cf93623bff9bd98cfbb783f5e9b93c7f50a4b7884fadce95244692
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript

The PDF contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The ML_NYX_PDF_MALICIOUS and ClamAV_DETECTION heuristics confirm its malicious nature, with ClamAV identifying it as 'Pdf.Dropper.Agent-5343179-0'. The embedded JavaScript is likely responsible for downloading and executing a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-5343179-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-5343179-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0044_000.js
ff32c4b7d8214db66e07fb3f372200bf6cd3438df1195d5eda9c53d7dee21877
pdf-javascript-stream PDF /JS object 44 at offset 0x14C 28475 bytes