Malicious PDF — malware analysis report

Static analysis result for SHA-256 c05695a3b1f0af63…

MALICIOUS

PDF

3.3 KB
MD5: 22f8db0cf06a2b6beb535af93aae66b7 SHA-1: a953f46b5a78e935a82fadda6910d3c15c01db12 SHA-256: c05695a3b1f0af630f3e8b73a99ae917f7eecb914bf71d3745dc6132a6807893
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was flagged by ClamAV as Pdf.Exploit.Agent-36121 and a machine learning classifier indicated a high probability of maliciousness. Embedded JavaScript was detected, which is often used to exploit vulnerabilities within the PDF reader. The embedded JavaScript stream is likely responsible for the exploit execution, though its specific actions are not detailed here.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
a00bad77090681e76717ca201828d356f2a547e9c1fc3b7e78ceaac923a7cf65
pdf-javascript-stream PDF /JS object 7 at offset 0xA85 367 bytes