Malicious PDF — malware analysis report

Static analysis result for SHA-256 c366db3f6590b5ae…

MALICIOUS

PDF

3.2 KB
MD5: 2872a53853c7a7718ba320b6dcc14fad SHA-1: 3409b9242c12c2daa7104d41ad5cdcd82e239df8 SHA-256: c366db3f6590b5ae6a8444c8854fdeae0ab934bd401d47a425c7ffc80151c0b0
76 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious File

The PDF file contains embedded JavaScript, indicated by heuristic firings for PDF_JAVASCRIPT and PDF_JS. ClamAV detection as Pdf.Exploit.Agent-36121 further confirms its malicious nature. The embedded JavaScript is likely responsible for exploiting a vulnerability within the PDF reader to execute arbitrary code.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
b899da2f8793154e31ec1d7672a1983663522812b3c69b778a9e4312d08c7ca5
pdf-javascript-stream PDF /JS object 7 at offset 0x9C3 457 bytes