Malicious PDF — malware analysis report

Static analysis result for SHA-256 f32cb7aad3a93af7…

MALICIOUS

PDF

12.6 KB
MD5: 5b8031f39d9b9287ffd2a87e766de4cb SHA-1: d5a77f4b1cef3983d4ba64743bd4d0b575b43e1c SHA-256: f32cb7aad3a93af73cb8499843d180fb2c7c6781a30e495926423b018d281186
78 Risk Score

Malware Insights

MITRE ATT&CK
T1059 Command and Scripting Interpreter

The file is identified as a malicious PDF by ClamAV. Static analysis detected embedded JavaScript, indicating an attempt to execute malicious code. The PDF differential parser also failed, suggesting potential obfuscation or structural manipulation. The embedded JavaScript is likely responsible for the malicious behavior, possibly downloading and executing a secondary payload.

Heuristics 4

  • ClamAV: Pdf.Malware.Agent-9800932-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Malware.Agent-9800932-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PSSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
0b2d00a8cde80fd6d7baeeb492bbcc9113b3278d8495cda1e485157b67f09c2c
pdf-javascript-stream PDF /JS object 76 at offset 0x35A 11830 bytes