Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e4ec8be4a4640b0…

MALICIOUS

PDF

167.7 KB
MD5: d30dc1c6478fdbae4965fa0271e132a0 SHA-1: 0319bd1a7b4d8c4df3a4b81d3f9822b74a868f87 SHA-256: 9e4ec8be4a4640b045b2e10f7db43295254444c92059f83efdf9a54c4381a628
214 Risk Score

Malware Insights

MITRE ATT&CK
T1559.002 Component Object Model Hijacking T1204.002 Malicious File

The sample is a PDF file flagged by ClamAV as 'Pdf.Exploit.Agent-35955'. Static analysis detected embedded JavaScript and RichMedia (Flash) content, indicating an attempt to exploit vulnerabilities within the PDF reader. The embedded 'WpuVlEGnF.swf' file is likely the exploit payload. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9859

Heuristics 6

  • ClamAV: Pdf.Exploit.Agent-35955 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-35955
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
WpuVlEGnF.swf
bf9dea6ff47dfb47c2f51b1fa9a09527dfe5e95399ccb2d043ba956b197360c9
pdf-embedded-file PDF EmbeddedFile object 16 at offset 0x234BB 52647 bytes
Detection
ClamAV: Pdf.Exploit.Agent-35955
Obfuscation or payload: unlikely