Malicious PDF — malware analysis report

Static analysis result for SHA-256 9cc49f0d4d108cd5…

MALICIOUS

PDF

3.3 KB
MD5: a622bfa4802e504087efd4c53d2fcf07 SHA-1: 0456f42c331a51c5fc942784987b0cc355f9178b SHA-256: 9cc49f0d4d108cd55882cb8a47f43d673f484f284253bc3b4bbb4e4b91d69f62
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The critical ClamAV heuristic 'Pdf.Exploit.Agent-36121' indicates a known PDF exploit. The presence of embedded JavaScript, identified by 'PDF_JAVASCRIPT' and 'PDF_JS' heuristics, strongly suggests that the exploit leverages this script to perform malicious actions. The script is likely designed to download and execute a secondary payload, a common technique for initial access and further infection. The document body content is unreadable, providing no further context.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
1b8ce7b1854bb0e96c8e3c82cb842307db40f8483781ed9a06ac28bc2b26f4e6
pdf-javascript-stream PDF /JS object 7 at offset 0xA81 302 bytes