Win.Trojan.Agent-36280 — PDF malware analysis

Static analysis result for SHA-256 f784915f8a2422b7…

MALICIOUS

PDF

12.2 KB
MD5: 004283945b9ce9e5fb1c24b579082d78 SHA-1: 4533f5c0d7630849d5d50901c3ceb8691e47a0bf SHA-256: f784915f8a2422b7371091064b7662cf4218d793bb3d09a01669df561fe6f256
106 Risk Score

Malware Insights

Win.Trojan.Agent-36280 · confidence 98%

MITRE ATT&CK
T1204.002 Malicious File: Malicious File

The PDF contains embedded JavaScript, which is a common technique for delivering malicious payloads. The ML classifier and ClamAV detection strongly indicate malicious intent, specifically identifying it as Win.Trojan.Agent-36280. The embedded JavaScript is likely responsible for executing the malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Win.Trojan.Agent-36280 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36280
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
8cce33020f5e8d5381d039b49e66763253abcf202953f8409ed0403075183456
pdf-javascript-stream PDF /JS object 76 at offset 0x383 11371 bytes