Malicious PDF — malware analysis report

Static analysis result for SHA-256 fada7a3093839d62…

MALICIOUS

PDF

3.2 KB
MD5: 550c3b7eeedaa46ac9bfe56528b16ea4 SHA-1: a1632425986487067d09eddcc3de703ef7302db0 SHA-256: fada7a3093839d6252e967d79dd5362d7dc635c2f43e5ea243127ca61097529c
76 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious File

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings and the presence of a JavaScript object. ClamAV detection as 'Pdf.Exploit.Agent-36121' strongly suggests exploitation of a PDF vulnerability. The embedded JavaScript is likely responsible for executing the malicious payload, leading to the 'malicious' verdict. The document body is unreadable, providing no further context on the lure.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
6e8a7995afcab75fba31c58347da68cb0c4bb1b1f5d3bb3cec4c37b66c9a609b
pdf-javascript-stream PDF /JS object 7 at offset 0x9C4 491 bytes