Malicious PDF — malware analysis report

Static analysis result for SHA-256 dfa4fbf3cc08f517…

MALICIOUS

PDF

1.2 KB
MD5: 3dba0d600e139c9dca8ac4c826c464e6 SHA-1: 100bf3d51787e93081c71e249698a3ebd2b2fbb9 SHA-256: dfa4fbf3cc08f5170cbbbfe630a4606491210abf1218c8148237e886d0633760
136 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious File

The critical heuristics indicate that this PDF file contains embedded JavaScript and uses an annotation subject to launch an eval stager. This suggests the file is designed to exploit a PDF vulnerability to execute arbitrary code, likely downloading and executing a secondary payload. The ClamAV detection further supports its malicious nature.

Heuristics 4

  • Annotation subject percent-decoding eval stager critical PDF_ANNOT_SUBJECT_MARKER_EVAL_STAGER
    OpenAction JavaScript forces annotation enumeration, reads an annotation /Subject payload with getAnnots(), rewrites marker bytes into percent escapes, decodes it with unescape(), and dispatches it through eval. This is a high-confidence exploit-kit staging pattern. It is intentionally not mapped to CVE-2009-1492 unless getAnnots() itself carries the crafted integer or long argument shape for that vulnerability.
  • ClamAV: Pdf.Exploit.Agent-36065 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36065
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
9c67560e8c63b720885d3efc1627b844b86a6ec08e99e5b65a22eae832045756
pdf-javascript-stream PDF /JS object 7 at offset 0x1A3 431 bytes