Win.Trojan.Agent-36280 — PDF malware analysis

Static analysis result for SHA-256 e927bc4e87660a38…

MALICIOUS

PDF

12.8 KB
MD5: af5f293e149e4dffa96eb18a8eb8138c SHA-1: 48c74ac13312f2598f163973d68570042c41ecd2 SHA-256: e927bc4e87660a38b9653e8342e68bef03f6f35c16b66172655d4c1ced2bdf51
106 Risk Score

Malware Insights

Win.Trojan.Agent-36280 · confidence 99%

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF was flagged by a machine learning classifier with high confidence and detected by ClamAV as Win.Trojan.Agent-36280. It contains embedded JavaScript, indicating an attempt to execute malicious code upon opening, likely to download and execute a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Win.Trojan.Agent-36280 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36280
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
562584451e85201a301e8fdcb126d0baf5ab40362dc9d32aa4d1699196b13dd6
pdf-javascript-stream PDF /JS object 76 at offset 0x383 11932 bytes