Malicious PDF — malware analysis report

Static analysis result for SHA-256 a8eb5a61055cfa22…

MALICIOUS

PDF

45.0 KB
MD5: d6ff3f7d6b66de3d6e3f96e4b0b3a95e SHA-1: c02be9c70cd391815006f0868b921a7b60e387cd SHA-256: a8eb5a61055cfa221ba565211efeb92642c810cee3e4922ea3f3d51e88991e51
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was flagged as malicious by multiple heuristics, including a critical ClamAV detection for 'Pdf.Exploit.Agent-36128'. It contains embedded JavaScript, which is a common technique for exploiting PDF vulnerabilities. The ML classifier also strongly indicated maliciousness. The embedded JavaScript is likely responsible for executing the exploit.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36128 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36128
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
087055ac5609807317e7403fdbf26683465b956d58c265234ea008c7d79a4db8
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 45305 bytes
legacy_pdfkit_stage_000.js
773b0e89347d0a24aa66891d58df500277f0c80111fe1f1730692d3bffd8d326
deobfuscated-js double percent-decoded annotation JavaScript at offset 0x1E7 33047 bytes