Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb5ce426f2ccc4dc…

MALICIOUS

PDF

45.0 KB
MD5: 0db9f15eebed12ff9b83cafb79b78efb SHA-1: d1bca6ab1fafdd5ba937fd3b9823ff7cec32e311 SHA-256: cb5ce426f2ccc4dc6159d08469fa775264634cd4f50dc4913798357b49f49b4f
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. ClamAV detection as 'Pdf.Exploit.Agent-36128' strongly suggests exploitation of a known PDF vulnerability. The large embedded JavaScript streams further support the likelihood that the script is designed to download and execute a secondary payload, a common attack vector for PDF-based malware.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36128 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36128
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
0008bf21611b3b88e219a8be806c163b21a6dca765ac6567f108c9610b347906
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 45305 bytes
legacy_pdfkit_stage_000.js
c7465a542bbffcd3cbfda4f7ebd00f84286e54102395c37c75fa112c62938c1e
deobfuscated-js double percent-decoded annotation JavaScript at offset 0x1E7 33047 bytes