Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3033af0b0674235…

MALICIOUS

PDF

14.4 KB Created: 2009-11-15 19:41:70 Authoring application: PDF Library 4.3.9 (via PDF Library 3.9.7)
MD5: 46b5814960ccfadea91b64000aa16c3e SHA-1: c7f23803376571cace930577022159d7e3f8c633 SHA-256: f3033af0b067423595c641755681c74b30720e5dff7f254d232ecdbf8f4f727d
136 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was detected as malicious by ClamAV with the signature Win.Trojan.Agent-36166. Static analysis revealed embedded JavaScript, indicating the document's primary function is to exploit vulnerabilities or deliver a secondary payload. The JavaScript action and embedded JS stream heuristics confirm the presence of executable code within the PDF. The exact behavior of the JavaScript is not fully discernible due to potential obfuscation, but its presence strongly suggests a malicious intent, likely involving the download and execution of further malware.

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36166 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36166
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
56a6260370e1fed8a354408ee6a90eadd0aecbe9e64480fc0767f08fe0d40059
pdf-javascript-stream PDF /JS object 7 at offset 0x1A5 74760 bytes
Detection
ClamAV: Win.Trojan.Agent-36166
Obfuscation or payload: unlikely