Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcbac1663d58b933…

MALICIOUS

PDF

27.7 KB
MD5: a729b076d7049951de1843e76a306ab4 SHA-1: e79c9e942cb3925e8f19c567c82528d2d70b13d7 SHA-256: fcbac1663d58b9334cda16dadf13c67dbec132f101125be25b5520010547157e
136 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF document contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. ClamAV detections (Win.Trojan.Agent-36100) confirm the malicious nature of the file. The embedded JavaScript is likely responsible for executing the malicious payload, although its specific actions are not detailed in the provided evidence. The document body content appears to be obfuscated or malformed, providing no clear user-facing lure.

Heuristics 4

  • ClamAV: Win.Trojan.Agent-36100 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36100
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
ece224ebdf794915ad1c3e8d09c55b8140890d9b870e89547a1c621e571f0ecf
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 27621 bytes
Detection
ClamAV: Win.Trojan.Agent-36100
Obfuscation or payload: unlikely
legacy_pdfkit_stage_000.js
27fa41614f96ccb395c957d7e9245f809e0cccb06d4ae8ceec8bd4aa876c2fed
deobfuscated-js double percent-decoded annotation JavaScript at offset 0x1E7 15189 bytes