Malicious PDF — malware analysis report

Static analysis result for SHA-256 ce8d4334cfe9c28d…

MALICIOUS

PDF

12.5 KB
MD5: 41d6db01a283860bc173ac79097fe28e SHA-1: 8a2253f4fb943a0d00697e831447a023c3352713 SHA-256: ce8d4334cfe9c28d1009ad3befb279955b8e6ce37be68a0fb3a0876eaec53e57
76 Risk Score

Malware Insights

The PDF file contains embedded JavaScript, indicated by heuristic firings for PDF_JAVASCRIPT and PDF_JS. ClamAV detection as Win.Trojan.Agent-36281 confirms its malicious nature. The embedded JavaScript is likely responsible for executing malicious code, potentially leading to further compromise.

Heuristics 3

  • ClamAV: Win.Trojan.Agent-36281 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36281
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
ed380d9a759208cea05c34b2e6919ace5f5d7ea58be586866a4d7dd7fdc248ea
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11699 bytes