Malicious PDF — malware analysis report

Static analysis result for SHA-256 b1cff3f4f56668de…

MALICIOUS

PDF

107.3 KB Created: 2009-12-21 16:55:35 +08:00 Authoring application: Acrobat PDFMaker 7.0ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿcer(Acrobat Distiller 7.0 (Windows) (via Acrobat Distiller 7.0 (Windows))
MD5: 16b956f5c4a219eaa3382a59f144375b SHA-1: b19f2128a0c0578c1f90069d7cdbd6fc588dc045 SHA-256: b1cff3f4f56668def4526986721d11da07ea932da13b3c7be217f1dc689ad42f
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript

The file is identified as a malicious PDF by ClamAV with the signature Pdf.Exploit.Agent-22197. Static analysis detected embedded JavaScript, indicating an attempt to exploit vulnerabilities within the PDF reader. The embedded JavaScript stream is the primary indicator of malicious activity, likely leading to the download or execution of a secondary payload.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-22197 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-22197
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/pdfx/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/photoshop/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0043_000.js
6a4feff50242ca48bccb7b8303874c63d44c492cea43499d20ce94d354dc031d
pdf-javascript-stream PDF /JS object 43 at offset 0x2430 2172 bytes