Malicious PDF — malware analysis report

Static analysis result for SHA-256 93f96e2a235132db…

MALICIOUS

PDF

14.4 KB Created: 2009-11-15 19:41:70 Authoring application: PDF Library 4.3.9 (via PDF Library 3.9.7)
MD5: 912404b833fd95fbb1ecaab8be64443c SHA-1: b15b76ee9c22acf2c3b8d35409c8ac9b405a45cd SHA-256: 93f96e2a235132db3768944b9b2e25090e8af7ae8e21c8be00efeffe72b68b89
136 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was detected as malicious by ClamAV with the signature Win.Trojan.Agent-36166. Static analysis revealed embedded JavaScript, indicating an attempt to execute code. The JavaScript is likely responsible for downloading and executing a second-stage payload, contributing to the overall malicious nature of the document. The specific payload or its distribution method could not be fully determined due to the nature of the embedded script.

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36166 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36166
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
c170bc7d0aaf0ba72432f3f0b0334540d9e7355e2411167f12dd84c0aca782c7
pdf-javascript-stream PDF /JS object 7 at offset 0x1A5 74339 bytes
Detection
ClamAV: Win.Trojan.Agent-36166
Obfuscation or payload: unlikely