Win.Trojan.Agent-36281 — PDF malware analysis

Static analysis result for SHA-256 92ed1d7697679dbd…

MALICIOUS

PDF

12.0 KB
MD5: a1d2ba40cfbacb71751fdda887661ad5 SHA-1: cae2832f409337e1e6c7a061f68196ed12c7ef0f SHA-256: 92ed1d7697679dbda8006cfc27c3afee7548d284eb4e0d12a82bae6b3e1c9544
106 Risk Score

Malware Insights

Win.Trojan.Agent-36281 · confidence 98%

MITRE ATT&CK
T1059 Command and Scripting Interpreter

The PDF contains embedded JavaScript, indicated by multiple heuristic firings and the presence of an embedded JS stream. The ML classifier and ClamAV detection strongly suggest malicious intent, classifying it as Win.Trojan.Agent-36281. The embedded JavaScript is likely responsible for executing the malicious payload, potentially exploiting PDF vulnerabilities.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Win.Trojan.Agent-36281 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36281
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
c48faf3121635952001fab0a66d055880c1a214e78b0ae7fe6346be307e02088
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11232 bytes