Malicious PDF — malware analysis report

Static analysis result for SHA-256 91058a9dfd0ca4db…

MALICIOUS

PDF

12.4 KB
MD5: 4dae8f7ec3c40b39d0255cd41c47c10e SHA-1: b1eebc70bbbc3c72c9cfb92b2d7eb89ad6403fc8 SHA-256: 91058a9dfd0ca4dbb5246e0ee3cc478158ac6a974b31ebd27be028a8bce870b6
76 Risk Score

Malware Insights

The PDF contains embedded JavaScript, indicated by multiple heuristic firings. ClamAV detection as 'Win.Trojan.Agent-36280' strongly suggests malicious intent. The embedded JavaScript is likely responsible for executing the malicious payload, although its specific actions are not detailed in the provided evidence.

Heuristics 3

  • ClamAV: Win.Trojan.Agent-36280 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36280
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
d53f329804df11e4960a5a72d8b0d2ea9be25d5d1f907290f9a692c1f3fc8588
pdf-javascript-stream PDF /JS object 76 at offset 0x383 11538 bytes