Malicious PDF — malware analysis report

Static analysis result for SHA-256 06edd79389672ff2…

MALICIOUS

PDF

29.4 KB Created: 2010-02-13 12:49:17 +03:00 Authoring application: [\?_#\^~] (via c273a867d4f81ad1055432bd598e114e)
MD5: 3859b6fb9d74537e2f2228068556f850 SHA-1: 5f44b3b30d9bc61c2e3130f2cac5c5ae9f5ce24f SHA-256: 06edd79389672ff2dfa9428e946fe326af5d7001c523faba8de2a32c1bf018fb
82 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file contains embedded JavaScript, indicated by multiple PDF_JAVASCRIPT and PDF_JS heuristics. The JavaScript code, though obfuscated, appears to be responsible for downloading and executing a secondary payload. The presence of ASCIIHexDecode and ASCII85Decode filters with exploit indicators further suggests a vulnerability is being leveraged for code execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9985

Heuristics 5

  • ASCIIHexDecode filter (with exploit indicators) medium PDF_FILTER_HEX
    Hex-encoding filter present alongside exploit delivery indicators — often used to hide payload or shellcode bytes
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85
    ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0018_000.js
4b3891efcce5162f5b6e2ea977f0c09d59d48dddb86660baf897aec983ab87e3
pdf-javascript-stream PDF /JS object 18 at offset 0x24C6 34723 bytes