Malicious PDF — malware analysis report

Static analysis result for SHA-256 a6a20650e5dde9ef…

MALICIOUS

PDF

27.9 KB
MD5: e1659d09c4510c1bb7a50ea1068f70af SHA-1: a68357acf87e5b0baf41cac78c95d93e413e95d3 SHA-256: a6a20650e5dde9ef5fea8d520068f6153709028553aadfc5b7138559506e9299
166 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The ML classifier and ClamAV detection strongly suggest malicious intent, identifying it as Win.Trojan.Agent-36100. The embedded JavaScript is likely responsible for downloading and executing a secondary payload, a common technique for malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36100 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36100
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
dcaa36749e02e599d8b532c5f8d68b19fd3d1f26ce5e2d26ff3d64fbaa771c6b
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 27765 bytes
Detection
ClamAV: Win.Trojan.Agent-36100
Obfuscation or payload: unlikely
legacy_pdfkit_stage_000.js
fda3ff8abcf1103ec15c7f72e71a644f4fd4fb8d2f652846649f299a41eafdb1
deobfuscated-js double percent-decoded annotation JavaScript at offset 0x1E7 15261 bytes