Malicious PDF — malware analysis report

Static analysis result for SHA-256 eef01ace16a10609…

MALICIOUS

PDF

4.4 KB Created: 2010-04-23 06:59:32 Authoring application: Dakmiyfomimaba
MD5: 78bd17e13fedae8103d6a9e820280e5b SHA-1: a607ddc1ece03d51364d1aa261890e8ad345d393 SHA-256: eef01ace16a106093a031e70b40b56026fad1393b966e248fb0b5a2659a25055
116 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The critical ClamAV detection 'Pdf.Dropper.Agent-7321703-0' strongly indicates malicious intent. The PDF contains embedded JavaScript, identified by multiple heuristics, which is likely responsible for executing a stager. This stager's purpose is to download and execute a secondary payload, a common technique for malware delivery. The document body contains obfuscated text and repetitive strings, which are often used to hide malicious content or evade detection.

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7321703-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7321703-0
  • Page-word XOR JavaScript eval stager high PDF_PAGE_WORD_XOR_EVAL_STAGER
    PDF JavaScript enumerates rendered page words with getPageNthWord/getPageNumWords, extracts encoded byte fragments, XOR-decodes the stage with char-code helpers, and evals the result. This is an old exploit-kit staging pattern and is not normal document JavaScript.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0010_000.js
77692aa6eee912f470430c71119e8b9c8ba346a577cd63ae147470c7ef4ca3c3
pdf-javascript-stream PDF /JS object 10 at offset 0xC9D 896 bytes