Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf181ad6983a1e04…

MALICIOUS

PDF

3.2 KB
MD5: e45f10ab36b8b3ec501687af097c9112 SHA-1: 96e2f89d661749bb62544ffc42ca1e7e22b5e56b SHA-256: bf181ad6983a1e04811251d6b00dbc0c658ad59dd8bde1f9522c6892c40f2636
108 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious File

The PDF file was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Exploit.Agent-36121'. An embedded JavaScript stream was also detected, indicating the likely execution of malicious code upon opening the PDF. The ML classifier strongly supports the malicious verdict. The exact attack vector is not fully detailed, but it is a known PDF exploit.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
061b4e85688f4081ac8408e6a1e738edcc6d3606c1855aae64a6a71f3b2a55a8
pdf-javascript-stream PDF /JS object 7 at offset 0x9C7 436 bytes