Malicious PDF / .PHP — malware analysis report

Static analysis result for SHA-256 04e0fead167e700a…

MALICIOUS

PDF / .PHP

31.1 KB
MD5: 0d0e26f29a639ebd40a5082dbdd0a948 SHA-1: 6c67c88902b684b3cd777a42b7448817451bf9ad SHA-256: 04e0fead167e700ad5718b22ce61159467740487209cdc96fb172cb47fc977d0
146 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript with multiple eval() calls, strongly indicating an exploit. The JavaScript is heavily obfuscated and truncated, making it difficult to determine the exact payload, but the presence of exploit cluster heuristics and ML classification confirms malicious intent. The primary function appears to be executing arbitrary code via the JavaScript engine.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0032_000.js
edc9fb681ff2c45e1db14b8b128ec6bb89ecb249a39e5e3014fd8846d7ec178e
pdf-javascript-stream PDF /JS object 32 at offset 0x2CA 3027677 bytes