Malicious PDF — malware analysis report

Static analysis result for SHA-256 c400f5f33e77a8a5…

MALICIOUS

PDF

3.3 KB
MD5: 96e169f0214b9adfbc7db95ebb55091f SHA-1: 8f47298f030f74d1e0c4b1d071c863fbaf63a543 SHA-256: c400f5f33e77a8a50c0f3f8166e2f3849ef8070b2e207cf665cedceb57661f72
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was flagged by ClamAV as Pdf.Exploit.Agent-36121 and a machine learning classifier gave a high probability of maliciousness. Embedded JavaScript was detected, which is likely responsible for executing the exploit. The exact payload and delivery mechanism are not fully discernible from the available heuristics and embedded script.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
8177455b82554417725ecea172f412aeb477f9630b92cbfa4655dd3d39ef8e25
pdf-javascript-stream PDF /JS object 7 at offset 0xA84 369 bytes