Malicious PDF — malware analysis report

Static analysis result for SHA-256 9bbea2350307b05a…

MALICIOUS

PDF

14.5 KB Created: 2008-07-26 19:43:58 Authoring application: Scribus 1.3.3.12 (via Scribus PDF Library 1.3.3.12)
MD5: e17d4af65c5497893879e2720e20f319 SHA-1: 874fe3da17f388c0f75d53d1c37480037cf6febf SHA-256: 9bbea2350307b05aacb8bc26e683d74b80dff470a2a4fae670bea33e2ec11053
148 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1059.007 JavaScript

This PDF file was flagged as malicious by a ClamAV signature (Pdf.Exploit.Agent-36118) and an ML classifier. It contains embedded JavaScript with multiple obfuscation layers, including the use of eval() and string concatenation. The script's intent appears to be downloading and executing a second-stage payload, as indicated by the heuristic firings for PDF JavaScript actions and eval() calls. The specific JavaScript code reconstructs strings like 'Math.max' and 'charCodeAt', suggesting dynamic code execution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Exploit.Agent-36118 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36118
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0013_000.js
ba6d6fd9d191213999a64e234c9ffe1bfd932f5233fa0528bc82adaf26a49592
pdf-javascript-stream PDF /JS object 13 at offset 0x336 13275 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s). Carved artifact contains 13 long base64-like blob(s).