Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee095e747ef22d2d…

MALICIOUS

PDF

3.3 KB
MD5: 385b5ac4bdc36e4fd4606e533f6cb03f SHA-1: baad73e9a46d8734ff0d9945017c760f7fa4de5a SHA-256: ee095e747ef22d2dad2c03c8a57b39c0d85ac8e92669f9b807acb164a3e17f76
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Exploit.Agent-36121' and a high ML score. An embedded JavaScript object was also detected, indicating an attempt to execute malicious code. The ML classifier's output of 0.999922 strongly suggests malicious intent, likely involving an exploit.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
6b0a6e5228cd847e8af0d70aa2409c3633bb8fd2b9d2c097035278e718532165
pdf-javascript-stream PDF /JS object 7 at offset 0xA88 326 bytes