Malicious PDF — malware analysis report

Static analysis result for SHA-256 d6a94b6e71e65e34…

MALICIOUS

PDF

14.5 KB Created: 2009-11-15 19:41:70 Authoring application: PDF Library 4.3.9 (via PDF Library 3.9.7)
MD5: 4825c9f5c63fcb3ead215a8e87d31729 SHA-1: 265a9c5b3099f9acb4df03cd240173eb77cb49ad SHA-256: d6a94b6e71e65e34934212770a40a2c9771ad72d557c04419014506c30dac256
136 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript

The file is identified as malicious by ClamAV with the signature Win.Trojan.Agent-36166. Static analysis detected JavaScript actions and an embedded JS stream within the PDF structure. The presence of JavaScript indicates an attempt to execute code, which is consistent with the malicious verdict. No document body text was available for further analysis.

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36166 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36166
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
4265dcad8a225b10f8d15d000e2274dd97b60174f2239aa7bb8cd31ae7f20456
pdf-javascript-stream PDF /JS object 7 at offset 0x1A5 74781 bytes
Detection
ClamAV: Win.Trojan.Agent-36166
Obfuscation or payload: unlikely