Malicious PDF — malware analysis report

Static analysis result for SHA-256 cdb0b68ad6f5043b…

MALICIOUS

PDF

3.3 KB
MD5: a29861499e037637dd9135bea952e739 SHA-1: ba85b0ff476f7338a4909fd70d048c15d851f2ec SHA-256: cdb0b68ad6f5043bdd30a88dba4d5414737c109609793a6b0f2221e88b6f022b
106 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious File

The PDF file was flagged by ClamAV as Pdf.Exploit.Agent-36121 and a machine learning classifier. Embedded JavaScript, detected via heuristics, is likely responsible for executing the malicious payload. The specific JavaScript content was too obfuscated to determine its exact function, but its presence strongly suggests a delivery mechanism for further malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
0d0d4e303823b63950a1fb6cfd58d020bb5433b42b21bf713f32d31ba9fba27d
pdf-javascript-stream PDF /JS object 7 at offset 0xA85 318 bytes