Pdf.Dropper.Agent-7217726-0 — PDF malware analysis

Static analysis result for SHA-256 c2907123b244421a…

MALICIOUS

PDF

1.4 KB
MD5: 3d658551dadfe2d610150e1c538ce1eb SHA-1: 523ea31f69b495df99c7790e883dbcc4aab05d9a SHA-256: c2907123b244421a840db2d5cde4cd80eef2192fd9e16e62fe2bab5c6e52d0ee
196 Risk Score

Malware Insights

Pdf.Dropper.Agent-7217726-0 · confidence 95%

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The critical CVE_2009_4324 heuristic confirms exploitation of a known vulnerability in PDF media players. The unescape() call suggests obfuscation of the JavaScript payload. The ClamAV detection further confirms its malicious nature as Pdf.Dropper.Agent-7217726-0. The embedded JavaScript is likely responsible for downloading and executing a second-stage payload, a common dropper behavior.

Heuristics 6

  • media.newPlayer — CVE-2009-4324 critical CVE exact CVE_2009_4324
    PDF JavaScript calls media.newPlayer — CVE-2009-4324 is a use-after-free in Adobe Reader's multimedia plugin triggered by media.newPlayer(). Actively exploited as a zero-day in December 2009. (matched in decompressed stream)
  • ClamAV: Pdf.Dropper.Agent-7217726-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7217726-0
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj111111_000.js
eff4aa20d225a5c2c667fece8aeb596774e177d22d136bd0291dbdfc1b73f939
pdf-javascript-stream PDF /JS object 111111 at offset 0x160 1269 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
javascript_obj111112_001.js
b188035d6164acf230a9e4d6b1ded08105d75e3eff8f0a47b2813ca3e167b4b5
pdf-javascript-stream PDF /JS object 111112 at offset 0x489 254 bytes