Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec6f62775faac739…

MALICIOUS

PDF

12.5 KB
MD5: 495ae10648b175f640276f31cbb213d4 SHA-1: 9a9b2b8e6f2274e050b824d133bcd6d03cbaf8bf SHA-256: ec6f62775faac739fccd57748e88bee46b4b167ebbcc0ad24f9f12cb3e0906c8
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 Service Execution: JavaScript

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings. ClamAV detection as 'Win.Trojan.Agent-36280' strongly suggests malicious intent. The embedded JavaScript is likely used to exploit vulnerabilities within the PDF reader or to download and execute a secondary payload.

Heuristics 3

  • ClamAV: Win.Trojan.Agent-36280 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36280
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
eca97ccb37da4cb6941d60b34d66072adba20ee491fa04eb8c166741468b8583
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11649 bytes