Malicious PDF — malware analysis report

Static analysis result for SHA-256 8bb8eab1572d594c…

MALICIOUS

PDF

12.3 KB
MD5: dc10502da6b4893c8301e7ae6a8f5597 SHA-1: e2de767ab2b97ba482f8af1c6c803a7a5b647483 SHA-256: 8bb8eab1572d594cc731ab4dac6cd803843252c07a0983869aa0d3be79ddc136
106 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious Link: Malicious File

The PDF file was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Exploit.Agent-36723'. It contains embedded JavaScript, indicating an attempt to exploit vulnerabilities within the PDF reader. The ML classifier also strongly indicated maliciousness. The primary attack vector appears to be leveraging JavaScript execution within the PDF to deliver a payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36723 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36723
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
02cfa2672482ed0d37a72b73722b55b1bc18008482730498f2255c9411ed50df
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11516 bytes