Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed304af8f741e002…

MALICIOUS

PDF

27.9 KB
MD5: eb647c83169d7722486c6fab4c45ae0d SHA-1: bd88cce170e8feb15c755ad5885c21f1d59a3c35 SHA-256: ed304af8f741e00210dfe465129aa947e5a47b7fd2350707e902490fec742e51
166 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was flagged as malicious by multiple engines, including ClamAV which identified it as Win.Trojan.Agent-36100. Heuristics indicate the presence of embedded JavaScript, suggesting an attempt to execute malicious code. The ML classifier also strongly indicated maliciousness. The embedded JavaScript is likely responsible for downloading and executing a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36100 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36100
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
dffb52aaddfe9fd4a7bb26f6b69d79a6fc33a2dbc400bffa9e013ae5aaceb27e
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 27765 bytes
Detection
ClamAV: Win.Trojan.Agent-36100
Obfuscation or payload: unlikely
legacy_pdfkit_stage_000.js
8993f6311b9d36e92fd518eeb8a122a2dd662d83debd2c69917abde890a684db
deobfuscated-js double percent-decoded annotation JavaScript at offset 0x1E7 15261 bytes