Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d1abcb5e3d3b3fe…

MALICIOUS

PDF

14.6 KB Created: 2009-11-15 19:41:70 Authoring application: PDF Library 4.3.9 (via PDF Library 3.9.7)
MD5: fd46c563165f3be116a4b06d97946fcf SHA-1: 06d8bee5a330f2d0a5a8274d60c6b33a98585f2a SHA-256: 9d1abcb5e3d3b3fedc25df101e2f831641c774d644b99d5ae7848b5743f5eadb
166 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was flagged by multiple heuristics, including ML classifiers and ClamAV, indicating malicious content. Specifically, the presence of embedded JavaScript actions and streams points to an attempt to execute code. The ClamAV detection of 'Win.Trojan.Agent-36166' strongly suggests the file is a known trojan. The embedded JavaScript is likely responsible for downloading and executing a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36166 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36166
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
0dfee74263c4a54912450010e59c7736abcc92c475fb11268ec9ad7c080b3ae9
pdf-javascript-stream PDF /JS object 7 at offset 0x1A5 75888 bytes
Detection
ClamAV: Win.Trojan.Agent-36166
Obfuscation or payload: unlikely