Malicious PDF — malware analysis report

Static analysis result for SHA-256 c6e5e40647bc0c57…

MALICIOUS

PDF

3.2 KB
MD5: 3985b4c761351fa9a04c52a7b2808b48 SHA-1: 4b4e89a5b2ed424ded9645f90a220c619b9b298e SHA-256: c6e5e40647bc0c57f57b28cb8a3d6573ca8a8370d5df09e154b3ca2ddca5cf6a
76 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious File

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings related to PDF JavaScript actions and streams. ClamAV detection as 'Pdf.Exploit.Agent-36121' strongly suggests exploitation of a known PDF vulnerability. The embedded JavaScript is likely responsible for executing the malicious payload, leading to the 'malicious' verdict. The exact behavior of the script could not be determined due to its obfuscation or truncation.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
7f59753189b6008016eb2af19a3094dd07acc36038066371472743d09852a69d
pdf-javascript-stream PDF /JS object 7 at offset 0x9C2 468 bytes