Malicious PDF — malware analysis report

Static analysis result for SHA-256 a8b4b9924a9163e5…

MALICIOUS

PDF

12.6 KB
MD5: ef5c9cedd83d38606c4f3931902dfd22 SHA-1: 6a74ac9f9f0b3843d3c2bb667a637ac254f77466 SHA-256: a8b4b9924a9163e5492e57b17c8c7f46443a0f6182b3d1080d78a32758c42404
106 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious JavaScript

The PDF file was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Exploit.Agent-36723' and a high ML score indicating maliciousness. It contains embedded JavaScript, which is commonly used in PDFs to deliver exploits or download secondary payloads. The presence of JavaScript actions and embedded JS streams strongly suggests an exploit attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36723 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36723
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
99cffd6c2c98fe21ae993632b75735bcd17c48f7c514987941c926d1482ff511
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11818 bytes