Malicious PDF — malware analysis report

Static analysis result for SHA-256 b0748010bf38a043…

MALICIOUS

PDF

12.3 KB
MD5: 51c379a4be5c9cbda968526d0b79d960 SHA-1: 3203902102e0a691de9cfa9e543f7647b6547570 SHA-256: b0748010bf38a043e4bc6568d626e851a517b3c5da5ec8ce51df6a66a7a16591
136 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious JavaScript

The file is identified as a malicious PDF by ClamAV with multiple detection names. Static analysis reveals embedded JavaScript, indicating an attempt to execute malicious code upon opening the document. The embedded JavaScript is likely responsible for exploiting a PDF vulnerability to achieve arbitrary code execution.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-36365 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36365
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
931a9a647943c938c782dc6558385534a3d9d7b50b5754fa025eca60d5854bc4
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11509 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36364
Obfuscation or payload: unlikely