Malicious PDF — malware analysis report

Static analysis result for SHA-256 d6cd92adf12b7cad…

MALICIOUS

PDF

51.6 KB Created: 2009-10-20 19:59:11 +04:00 Authoring application: tendChunk (via 27324bfa32fc43f34ea23a2b279c4992)
MD5: a9e2a597df08f99944a06f175d53d003 SHA-1: 4add8c0a9c98ec74447b78778ecf091631d78cad SHA-256: d6cd92adf12b7cad25e329370f7b8d57eba703745a26caffef37112573e63b93
114 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious Link

The PDF file was flagged as malicious by ML classifiers and ClamAV, specifically identified as 'Pdf.Exploit.Agent-2079'. It contains embedded JavaScript, indicating an attempt to exploit vulnerabilities within the PDF reader or execute malicious code. The presence of JavaScript actions and embedded JS streams strongly suggests the file's purpose is to deliver a payload or exploit. The exact nature of the exploit or payload is not detailed in the provided evidence, but the overall pattern points to a common PDF-based attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9747

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-2079 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-2079
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0048_000.js
bae2cdb72e4dce59ed0f1ddfab96591a65d78f76c9f38692a8d8eecf7e7b3ecc
pdf-javascript-stream PDF /JS object 48 at offset 0x7054 21394 bytes