Malicious PDF — malware analysis report

Static analysis result for SHA-256 9b7b486c13f77e1c…

MALICIOUS

PDF

3.2 KB
MD5: 1b30a4a1a9f7564488732cf5f551e8f6 SHA-1: 69a3fb0b67e0cde132c822b14af828be22e34fc5 SHA-256: 9b7b486c13f77e1c72fa7b944d568bcb3a89e600873f2ed5be8bc7297dabd532
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. ClamAV detection further confirms its malicious nature. The embedded JavaScript is likely responsible for executing an exploit, leading to the download or execution of a secondary payload. However, the specific JavaScript content was not provided for detailed analysis, limiting the ability to reconstruct specific IOCs or identify the exact exploit.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
861807b754f72b8da001f7e81e6740457837e0462928d91daaeb24fa6a2d5004
pdf-javascript-stream PDF /JS object 7 at offset 0x9C4 487 bytes