Malicious PDF — malware analysis report

Static analysis result for SHA-256 d3e07b65c762706f…

MALICIOUS

PDF

81.2 KB Created: 2010-02-09 16:22:45 +03:00 Authoring application: overMore (via 13efec348e66852991bc20ed97caa574)
MD5: 9df8e236f3c6bc425925e3f6bb36a69c SHA-1: cfcecc0b771ec3f4fbbbaffa923fc721c7fcf5a1 SHA-256: d3e07b65c762706fb55baff325b9419153342899027454f1f0e2b39aa58ef2fa
114 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was flagged as malicious by multiple engines, including ClamAV which identified it as Pdf.Dropper.Agent-7308189-0. Static analysis revealed embedded JavaScript streams, indicating the document's primary function is to execute arbitrary code. The ML classifier also strongly indicated maliciousness. The presence of JavaScript actions and embedded JS streams points to a dropper or downloader functionality, aiming to fetch and execute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7308189-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7308189-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
c4258cc1be2a14264d91ca584a89964ae65c0e176088766a69baaabaafc6f63f
pdf-javascript-stream PDF /JS object 11 at offset 0x154E 3902 bytes
javascript_obj0012_001.js
4f799c4ba0c439c52f7daf6703be804b4cfdcec20d3bb0f812a4dc63e8a583ea
pdf-javascript-stream PDF /JS object 12 at offset 0x24FF 66584 bytes
javascript_obj0013_002.js
a284ff9f972dc09ddb2de2a8d87418c5550678c42c2d66b52bf66ff4e99267eb
pdf-javascript-stream PDF /JS object 13 at offset 0x12953 1904 bytes
javascript_obj0014_003.js
3ee08b7951b839e498436b512d4b590abf3cb95c22f347b828f8490d432ac9cd
pdf-javascript-stream PDF /JS object 14 at offset 0x1310D 1228 bytes
javascript_obj0015_004.js
3da0c64c4970cbec1fd3e9fbab8358fc1c8b295591afc656ef5ffee449f0807a
pdf-javascript-stream PDF /JS object 15 at offset 0x13619 2362 bytes