Malicious PDF — malware analysis report

Static analysis result for SHA-256 fdd715487f6bd246…

MALICIOUS

PDF

3.2 KB
MD5: 42614daa56e5291f715e5c5d0b37e6c0 SHA-1: 9b61bafde7b7499a9c4df7bc3486ef368dcf0af3 SHA-256: fdd715487f6bd24665704e6567b52124829c6d12f4267fe5f27691323e41c4b8
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. ClamAV detection as 'Pdf.Exploit.Agent-36121' further confirms its malicious nature. The embedded JavaScript is likely responsible for executing the exploit, although its specific actions are not detailed in the provided evidence. The document body is unreadable, providing no further context on the lure.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
a775c3b503e6cb6e6c7933b75ab603adc8bc128ff2503a8eca3059593dbfeb5b
pdf-javascript-stream PDF /JS object 7 at offset 0x9C8 447 bytes