Malicious PDF — malware analysis report

Static analysis result for SHA-256 ab209376c82e218f…

MALICIOUS

PDF

3.3 KB
MD5: b92e048dfe2ab6171a4b37afc955ed41 SHA-1: 0633ba5ea34827250d7bd4d276f4150cfe02d11c SHA-256: ab209376c82e218f9ffa4310f5e090304b7ef8c5f7f7bee265852a3b88ca182c
106 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious JavaScript

The PDF file was flagged as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. Heuristics indicate the presence of embedded JavaScript, which is commonly used in PDF exploits to download and execute further stages. The embedded JavaScript is likely responsible for the malicious behavior, though its exact function could not be determined due to obfuscation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
a8f51396f62d1757bd33d45916fb2bade19986df5d4c2b7710cd80b98f6d79ac
pdf-javascript-stream PDF /JS object 7 at offset 0xA87 336 bytes