Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7a34e2f5a2effdd…

MALICIOUS

PDF

3.2 KB
MD5: ef2165aad4309b03bd70d6c8c057924d SHA-1: 851fc66b0f810684c75c04bcf569c69207b277a1 SHA-256: f7a34e2f5a2effddd51fc50ff9451b9a7e27cbdfd6b00a0b33a48f338c5db876
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is identified as a malicious PDF by ClamAV and a machine learning classifier. Heuristics indicate the presence of JavaScript actions and embedded JS streams within the PDF, suggesting an exploit is being used to execute arbitrary code. The specific ClamAV detection name 'Pdf.Exploit.Agent-36121' points to a known exploit within PDF documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
c45d94cecc80eafe9abaf92b2d1ccb8ee5f04c80f146d450e2c49d9408e8aa26
pdf-javascript-stream PDF /JS object 7 at offset 0x9C9 468 bytes