Malicious PDF — malware analysis report

Static analysis result for SHA-256 90f1c20e74dcd1dd…

MALICIOUS

PDF

7.0 KB Created: 2008-31-20 53:85:00 Authoring application: Scribus 1.3.3.12 (via Scribus PDF Library 1.3.3.12)
MD5: 46d904bf25e0e73e823a689b790c8b29 SHA-1: a7dd7c620b703b1dd54e884dade6c1737839dac2 SHA-256: 90f1c20e74dcd1dd31c2828e8512f32c043db8f86ae6ca1a02c74d8ad1080690
178 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The sample is a PDF file that contains embedded JavaScript. Heuristics indicate the presence of JavaScript actions, embedded JS streams, and critically, an eval() call, which is often used to deobfuscate and execute malicious code. ClamAV detection confirms this, identifying the file as 'Pdf.Exploit.Agent-35587'. The obfuscated JavaScript is likely designed to download and execute a second-stage payload, a common technique for PDF-based malware.

Heuristics 6

  • ClamAV: Pdf.Exploit.Agent-35587 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-35587
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0013_001.js
174080f7b1c39e1489df74c4cf0281f90f460deacc69da5af78f8d8f66106eb0
pdf-javascript-stream PDF /JS object 13 at offset 0x392 5578 bytes
Detection
ClamAV: Pdf.Exploit.Agent-35587
Obfuscation or payload: likely
Carved artifact contains 5 eval/decoder/string-building token(s).