Malicious PDF — malware analysis report

Static analysis result for SHA-256 bed2f1a1a9fe3908…

MALICIOUS

PDF

117.1 KB
MD5: 7bf6eadbe503ca43c7676022fbeb19e7 SHA-1: a0c4fef97c7e8079c2749b69c30921e082d7e7f8 SHA-256: bed2f1a1a9fe39085716c377fdf03f64ba8f66423e4899fa75ded9f47227d79f
76 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious JavaScript

The sample is a PDF file identified by ClamAV as Pdf.Exploit.Agent-36388. Static analysis detected embedded JavaScript actions and streams, indicating an attempt to exploit PDF vulnerabilities. The embedded JavaScript is likely responsible for executing malicious code, potentially leading to further compromise.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36388 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36388
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.