Malicious PDF — malware analysis report

Static analysis result for SHA-256 a15c3b80935113b9…

MALICIOUS

PDF

50.5 KB Created: 2009-11-13 15:43:36 +03:00 Authoring application: tendChunk (via 3d94d7a9d5b0826898e1203a05d83b84)
MD5: 38d8daf4a5c4afeebad4039869bcec70 SHA-1: 50fa0d3f79fcfa81ef6e6b9755aa335603a09f18 SHA-256: a15c3b80935113b9a9f4c186a610618c9eeb905fafd90b2bf1565072e43cf467
154 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, with a high-confidence heuristic detecting an eval() call. This suggests the script is designed to execute arbitrary code. The ML classifier and ClamAV detection strongly indicate malicious intent, likely involving the exploitation of a PDF vulnerability to download and execute a secondary payload. The specific exploit and payload are not detailed in the provided evidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Exploit.Agent-3860 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-3860
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0021_000.js
7424c36b14ccfec995385b5a7d279b47206f6e7da6a8c60b42155c80c542e760
pdf-javascript-stream PDF /JS object 21 at offset 0x361A 4096 bytes
javascript_obj0022_001.js
9e9472164ea5b58749039f240d82beec6aba639a58279732913580fbf27d9521
pdf-javascript-stream PDF /JS object 22 at offset 0xC393 40 bytes