Malicious PDF / .PHP — malware analysis report

Static analysis result for SHA-256 cc90d4b7a1ed6944…

MALICIOUS

PDF / .PHP

37.1 KB Created: 2010-04-11 20:43:02 +04:00 Authoring application: TCPDF (via TCPDF 4.8.032 (http://www.tcpdf.org))
MD5: 0230251e7eba2f99a939708fdc77f0ec SHA-1: fca62f4394bc064d576f199502a638c375e3fd94 SHA-256: cc90d4b7a1ed694472545b464595566b8967ac5b40b56e2cfff6001a67108766
84 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1559.001 Component Object Model Hijacking

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings including 'PDF_JAVASCRIPT' and 'PDF_JS'. The ClamAV detection 'Pdf.Exploit.Agent-22596' strongly suggests this is a known exploit. The embedded JavaScript is likely responsible for triggering the exploit, leading to the execution of malicious code. The exact nature of the exploit and its payload cannot be determined without further analysis of the JavaScript content, which was not fully provided.

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-22596 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-22596
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0010_000.js
754ac2d0b9e89c2d7d18831bab331a09bf99ed321668b0d464235200e312e440
pdf-javascript-stream PDF /JS object 10 at offset 0x89DA 1342 bytes