Win.Trojan.Agent-36281 — PDF malware analysis

Static analysis result for SHA-256 bf8344f5f80b0725…

MALICIOUS

PDF

12.6 KB
MD5: ab5a186e9ef2d909a7824311792e64cb SHA-1: 2d573f81c6b14cc4815696eca80cd7ac4a9eb175 SHA-256: bf8344f5f80b0725b6eea4488e45ee54d8c1277fa94a4143b1eafaac02cb3e84
106 Risk Score

Malware Insights

Win.Trojan.Agent-36281 · confidence 98%

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious File

The PDF file was flagged by multiple heuristics, including a critical ClamAV detection identifying it as Win.Trojan.Agent-36281. It contains embedded JavaScript, which is a common technique for executing malicious code within documents. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Win.Trojan.Agent-36281 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36281
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
515b0e3176b540e74ca8825b69fc9e590fb191ff637629c418ccb10b70e9d518
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11848 bytes