Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8e76e346ea055f1…

MALICIOUS

PDF

27.6 KB
MD5: 478cd807b7bf1c28c31ea8c93726bb49 SHA-1: a8e55d88293f08f2d15819fb331eeb41d819b890 SHA-256: c8e76e346ea055f10ad2b29fe15a5ebf86027e83614189972248f21459d97f44
136 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF contains embedded JavaScript, indicated by multiple heuristic firings. ClamAV detection as 'Win.Trojan.Agent-36100' strongly suggests malicious intent. The JavaScript is likely used to exploit a PDF vulnerability or download a secondary payload. The document body content is heavily obfuscated and does not provide clear user-facing lures.

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36100 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36100
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
36a48ed0fc5ec567ba7c387e7960240909591ae1e9b54fe94d3f36a9edf17bcb
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 27477 bytes
Detection
ClamAV: Win.Trojan.Agent-36100
Obfuscation or payload: unlikely
legacy_pdfkit_stage_000.js
689f7e3a2203b916f6529ea5c203fb29a1552993daa472a76dc0e8b62bd401e6
deobfuscated-js double percent-decoded annotation JavaScript at offset 0x1E7 15117 bytes