Malicious PDF — malware analysis report

Static analysis result for SHA-256 fc20ed0ab3a4a9fa…

MALICIOUS

PDF

79.3 KB
MD5: 53d024a3170983ef84255127ce343cec SHA-1: 4db01d762e3921c842e47f599f1792d68cdc9493 SHA-256: fc20ed0ab3a4a9faeb591f02be4fa0821315f3c4457499bb076f3595c962a55f
78 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was detected by ClamAV as Pdf.Dropper.Agent-7327741-0. Static analysis revealed embedded JavaScript, specifically a deobfuscated file named legacy_pdfkit_stage_000.js. This JavaScript is indicative of a dropper mechanism, likely designed to download and execute further malicious content. The obfuscation and embedded script strongly suggest a multi-stage attack.

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7327741-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7327741-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
fad5b07ce96e9dfeacc100b443da234583d3a230bd99ddf91602bb5ee8c71b30
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 3766 bytes
legacy_pdfkit_stage_000.js
d6a9bf032a108e2093c3876bad0b56154846960ff050a10607ba06d9d9959569
deobfuscated-js repeated-marker hex decoded JavaScript at offset 0x10D1 2552 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s).