Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8837c0befb717a6…

MALICIOUS

PDF

16.0 KB
MD5: a786a87289dede606406299af4833eff SHA-1: 0f51b2c2ba75f055c14f49e6a5e88eb96b73b20d SHA-256: e8837c0befb717a67296b8be2807151b1a0a465e3be0a75eda2f35d7f1e74473
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Exploit.Agent-36324' and a high ML score, indicating malicious intent. An embedded JavaScript stream was also detected, likely responsible for executing exploits and downloading further malicious content. The presence of JavaScript actions and streams strongly suggests an exploit attempt within the PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36324 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36324
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
6bb7bbd0983f9fc838e0e165f20e5a4f4f1ba6b2e6d5493d4939a8033be74986
pdf-javascript-stream PDF /JS object 76 at offset 0x2D4 15400 bytes