Malicious PDF — malware analysis report

Static analysis result for SHA-256 ac408d76bc8c22f9…

MALICIOUS

PDF

3.3 KB
MD5: 7e609b6d2d42ec90039210edac4c80c2 SHA-1: 10e4d16d384282376384c4fa6f3537c18fff437e SHA-256: ac408d76bc8c22f9f4ff409b6413e0a107f0012c1cdee0eda46e2d84fb34a97b
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by heuristic firings for PDF_JAVASCRIPT and PDF_JS. ClamAV also detected this file as Pdf.Exploit.Agent-36121. The embedded JavaScript is likely responsible for exploiting a vulnerability within the PDF reader to execute malicious code. Due to the lack of readable document body text, the specific lure or payload cannot be determined, but the presence of exploit code is clear.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
ccdb8dc312b754d8349dcf11b32cae611186a5bd0883fc329829368b5d58bf0c
pdf-javascript-stream PDF /JS object 7 at offset 0xA85 359 bytes