Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc3e188cb9fa4f11…

MALICIOUS

PDF

2.7 KB Created: 5121-01-01 Authoring application: 108
MD5: aa78fa0d62e91bc2269500f5cf7f5921 SHA-1: b615239842f50c92c3dc2dee6facaa1c3ae380fc SHA-256: bc3e188cb9fa4f114eca2e41c63ceb4f95f57766fb60d7a5cbd1858b9ec5c7fd
96 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. ClamAV also detected it as Pdf.Exploit.Agent-36014. The embedded JavaScript, named javascript_obj0013_001.js, is obfuscated and likely responsible for executing the exploit. The exact nature of the exploit and its payload cannot be determined due to obfuscation, but it is designed to deliver malicious content.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-36014 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36014
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0013_001.js
fcd7a1778027685551c6436dacf5f48212c62223b98ce24436b8f0297c9b228c
pdf-javascript-stream PDF /JS object 13 at offset 0x328 4807 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 10 eval/decoder/string-building token(s). Carved artifact contains 3 long hex-escaped blob(s).