Malicious PDF — malware analysis report

Static analysis result for SHA-256 b09b3e5e25ba4b23…

MALICIOUS

PDF

3.3 KB
MD5: 37aace611a21380fcc29da16c319f556 SHA-1: 535a9dbfa49e0115a12689b878eec7bd15d3eb85 SHA-256: b09b3e5e25ba4b2387015f167a793688329b47909d1dfab596e4b10ccde42538
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

This PDF file was flagged as malicious by ClamAV and a machine learning classifier. It contains embedded JavaScript, which is likely used to exploit a vulnerability within the PDF reader. The JavaScript's exact function is not fully discernible due to obfuscation, but it is the primary mechanism for delivering the malicious payload. The ML classifier's high confidence score and the ClamAV detection strongly indicate a malicious exploit.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
688999941b3b34adb537e791797de3fb4cfb74c54739636b7b7c6d846e5ceefb
pdf-javascript-stream PDF /JS object 7 at offset 0xA87 316 bytes