Malicious PDF — malware analysis report

Static analysis result for SHA-256 d85832531f693128…

MALICIOUS

PDF

14.8 KB Created: 2008-07-26 19:43:58 Authoring application: Scribus 1.3.3.12 (via Scribus PDF Library 1.3.3.12)
MD5: 2f82b80384ba7526eac1c235ba84b8eb SHA-1: b322ed8af795ea1959f4c5ca1ac58915730cdd18 SHA-256: d85832531f693128853db013f2d4e975c9bb52295240bcd3ce6081e77df836ad
208 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

This PDF sample was flagged by ClamAV as Pdf.Exploit.Agent-36118, indicating a known exploit. Static analysis revealed embedded JavaScript with multiple eval() calls, suggesting obfuscation to hide malicious code. The ML classifier also strongly indicated maliciousness. The primary intent appears to be the execution of this obfuscated JavaScript, which likely downloads and executes a second-stage payload, a common technique for PDF-based malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 6

  • ClamAV: Pdf.Exploit.Agent-36118 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36118
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0013_000.js
42d53d4aa61a4bb961a1a138cfd48c24bf623e3e3a3b6036d8d521f626bc6a9b
pdf-javascript-stream PDF /JS object 13 at offset 0x336 13592 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s). Carved artifact contains 14 long base64-like blob(s).
javascript_obj0013_001.js
978b98b8a1ff9b0c51136914d62e419764fbd19c1c7afde26ef3d22f539fadb1
pdf-javascript-stream PDF /JS object 13 at offset 0x359 14298 bytes
Detection
ClamAV: Pdf.Exploit.Agent-36118
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s). Carved artifact contains 14 long base64-like blob(s).