Malicious PDF — malware analysis report

Static analysis result for SHA-256 c6f3357daa8d8049…

MALICIOUS

PDF

12.3 KB
MD5: 03970f8f29a1cbc893ef6d21597780ea SHA-1: 55242d693e69668c97ea33e265a00a334018aed8 SHA-256: c6f3357daa8d8049d305b211794a168478642674cdfb88d7041d476dac476f32
166 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious File

The PDF file was flagged as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. Embedded JavaScript, identified by heuristics, is likely responsible for executing the exploit. The primary IOC is the embedded JavaScript file itself, which likely contains the exploit code.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-36365 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36365
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
9af5e80b0388392b80ef5a16dd73c1a758ace51387f9b7f3c166ea6f230d585b
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11505 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36364
Obfuscation or payload: unlikely