Malicious PDF — malware analysis report

Static analysis result for SHA-256 bffdc1e712b2cc67…

MALICIOUS

PDF

14.4 KB Created: 2009-11-15 19:41:70 Authoring application: PDF Library 4.3.9 (via PDF Library 3.9.7)
MD5: 01587a7945e4ee1f28d3b44c105c5a7c SHA-1: 8b6334fe80b5079f6839edfdc2102dc25b72eba3 SHA-256: bffdc1e712b2cc679b6caf7c43e2a43851b66cd12d4b345c47120bc93c438d04
136 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript

The file is a PDF containing embedded JavaScript, indicated by multiple heuristic firings. ClamAV detections (Win.Trojan.Agent-36166) confirm its malicious nature. The embedded JavaScript, which is a large component, is likely responsible for executing the malicious payload. The specific intent of the JavaScript could not be fully determined due to its size and potential obfuscation, but its presence alongside the ClamAV detections strongly suggests it's used for malicious execution.

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36166 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36166
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
69c7084ec0751c8cd50eff7474c24025b4661927f07fce70124b988818e4b480
pdf-javascript-stream PDF /JS object 7 at offset 0x1A5 74532 bytes
Detection
ClamAV: Win.Trojan.Agent-36166
Obfuscation or payload: unlikely