Malicious PDF — malware analysis report

Static analysis result for SHA-256 9fedeac4e204670e…

MALICIOUS

PDF

3.3 KB
MD5: dab32a4631cbcdd516488650ebfd3aa7 SHA-1: 28934553217884e44eb333ced91b219a60e2451a SHA-256: 9fedeac4e204670efbe84d02af8338f8c27b13146fd3bb8a097474c2c7eb2689
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged as malicious by ML classifiers and ClamAV, specifically identified as Pdf.Exploit.Agent-36121. Embedded JavaScript was detected, indicating an attempt to exploit vulnerabilities within the PDF reader to execute arbitrary code. The exact nature of the exploit and its payload could not be determined due to the obfuscated nature of the embedded script.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
95990a761f932b9c4957f38c5013791751b78325c3565042c19d078e859fe364
pdf-javascript-stream PDF /JS object 7 at offset 0xA84 341 bytes