Malicious PDF — malware analysis report

Static analysis result for SHA-256 ab9ab2c74b08ebb5…

MALICIOUS

PDF

4.2 KB
MD5: 2361d63a77aaf1e42ddd965ff02f348b SHA-1: 89741a54680280cbad5a2e4c15ba5d8849fbcedd SHA-256: ab9ab2c74b08ebb5d154be937c77778f9be181afd5f4a587540e46e399b08bdb
116 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript T1204.002 Malicious File

The PDF was flagged by multiple heuristics, including ML and ClamAV, indicating malicious intent. The embedded JavaScript stream is the primary mechanism for the attack, likely responsible for downloading and executing a secondary payload. The ClamAV detection name 'Pdf.Dropper.Agent-7291781-0' further supports its role as a dropper.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7291781-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7291781-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
1bc4bf38a788adcc495fb84f1f085cb4c62f9f214ddac09c9e3dd447973e35e6
pdf-javascript-stream PDF /JS object 7 at offset 0x1CC 254 bytes