Malicious PDF — malware analysis report

Static analysis result for SHA-256 befb1de3608a8aa3…

MALICIOUS

PDF

15.8 KB
MD5: 5acef28088dfa9a534c60f583b5e3105 SHA-1: 6996059e1aba4c021e22c3aa44c8e9c66e73586e SHA-256: befb1de3608a8aa3f5a9d55f0215bc7c48f0103b94c0754a65338c6008967592
76 Risk Score

Malware Insights

The PDF file contains embedded JavaScript, identified by heuristic firings PDF_JAVASCRIPT and PDF_JS. ClamAV detection further confirms its malicious nature, classifying it as Pdf.Malware.Agent-7792561-0. The embedded JavaScript is likely responsible for executing a malicious payload, although its specific actions are not detailed in the provided evidence.

Heuristics 3

  • ClamAV: Pdf.Malware.Agent-7792561-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Malware.Agent-7792561-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
192ecd2b7ca8ce931d35114a29443748a0e173b2e9281bfe7fa6990fd444ae07
pdf-javascript-stream PDF /JS object 76 at offset 0x2E3 15174 bytes