Malicious PDF — malware analysis report

Static analysis result for SHA-256 dc4b5d22d7ac4389…

MALICIOUS

PDF

12.5 KB
MD5: 5572816d556bd2e4626ca71d52b7c064 SHA-1: 544cb873da3cae86133afd516938efa5103f7525 SHA-256: dc4b5d22d7ac4389ab288f565a045a09c4364f4481ab534e2d3aee41644066fb
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by heuristic firings for PDF_JAVASCRIPT and PDF_JS. ClamAV detection as Pdf.Exploit.Agent-36723 strongly suggests it's designed to exploit vulnerabilities. The embedded JavaScript is likely responsible for executing the exploit or downloading a secondary payload.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36723 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36723
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
d097003e8f85aa3ca4d01885c50ec4cd1d68f84536d9bb17f2f0b06c71614665
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11728 bytes