Win.Trojan.Agent-36280 — PDF malware analysis

Static analysis result for SHA-256 b4a0a1867883f193…

MALICIOUS

PDF

12.7 KB
MD5: b4ff2262f2da8658b2654cd970442428 SHA-1: c3ff538636a701c1f3f377c1424af95dd104653a SHA-256: b4a0a1867883f19362c67512fefab9183da01e7354f8be161952e88840d02812
106 Risk Score

Malware Insights

Win.Trojan.Agent-36280 · confidence 98%

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The file is a PDF containing embedded JavaScript, flagged by multiple heuristics and a machine learning classifier as malicious. ClamAV specifically identifies it as Win.Trojan.Agent-36280. The presence of JavaScript suggests an attempt to execute malicious code, likely to download and run a secondary payload, which is a common tactic for this type of threat.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Win.Trojan.Agent-36280 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36280
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
6441352cddb2a8976b3748b874ca945c407b3094d97bc9ba5ddc1904da577340
pdf-javascript-stream PDF /JS object 76 at offset 0x383 11848 bytes