Malicious PDF — malware analysis report

Static analysis result for SHA-256 c61c478feb923803…

MALICIOUS

PDF

5.1 KB Created: 2009-08-23 19:47:07 Authoring application: Elza 2.6.6.3 (via PDF Library 4.8.1.5)
MD5: 7777ebd05671006541bd6ffdf26ab96e SHA-1: 7a6372e5a6db2f3b755af28e132ab09aa8f1fdef SHA-256: c61c478feb92380354f9e8373a2544f7305c1395d86f46630bb09c84d583d3c3
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was detected as malicious by ClamAV with the signature Pdf.Dropper.Agent-7596866-0. Static analysis revealed embedded JavaScript, indicating the file is likely a dropper designed to execute a secondary payload. The JavaScript action and embedded JS stream heuristics confirm the presence and potential execution of malicious code within the PDF.

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7596866-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7596866-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0014_000.js
576abe2be061f7bf5f56919a3f9ca24cb62bf7fd3b8372b3aa596d3cd0f4302d
pdf-javascript-stream PDF /JS object 14 at offset 0x398 74451 bytes