Malicious PDF — malware analysis report

Static analysis result for SHA-256 d22cbf9077dd78b9…

MALICIOUS

PDF

12.3 KB
MD5: 9c53bead5ae2dc28237903ce8018cdcd SHA-1: c04e53abbb16c7ac6e5f88c72eea9b9b9b2e84cc SHA-256: d22cbf9077dd78b9e1681e7426dd245f2b467efa15071172be675d32b930d6db
106 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious File

The PDF file was flagged as malicious by multiple heuristics, including a high-severity ML classifier and critical ClamAV detection identifying it as Win.Trojan.Agent-36280. Embedded JavaScript streams were detected, indicating an attempt to execute malicious code upon opening the document. The primary attack vector appears to be leveraging PDF vulnerabilities to deliver a trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Win.Trojan.Agent-36280 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36280
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
32a7c21f3794533f59435473b8b9c904a57a98c6507532df114447dddbda6bfe
pdf-javascript-stream PDF /JS object 76 at offset 0x383 11467 bytes