Malicious PDF — malware analysis report

Static analysis result for SHA-256 a964e31964662993…

MALICIOUS

PDF

12.1 KB
MD5: 021e1aed7d16dca378da4316c7cd3f48 SHA-1: b4d806408a34c63ac1e9dcc8b9b13b1fca91df7b SHA-256: a964e31964662993d227b44c226af4e4140d79ea62d0f4711f295ee05a57e131
166 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious File

The PDF contains embedded JavaScript, indicated by multiple heuristic firings and the presence of an extracted JavaScript file. The ML classifier and ClamAV detections strongly suggest this JavaScript is malicious, likely exploiting PDF vulnerabilities to achieve arbitrary code execution. The primary IOC is the embedded JavaScript file itself.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-36365 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36365
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
8738bbdc04da5d4dac56e7c33236ec8b973fb39110369cc094deb12742a11254
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11257 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36364
Obfuscation or payload: unlikely