Malicious PDF — malware analysis report

Static analysis result for SHA-256 0981ffd085ae8603…

MALICIOUS

PDF

9.4 KB Created: 2010-05-14 18:41:54 Authoring application: abXHTglXW (via REEyzj1ufP)
MD5: c9a060eddb0b2b8a1fe62627fbdc5fed SHA-1: 567cc3cd57fcbf1c4308c14416c74a8564997cf0 SHA-256: 0981ffd085ae86032f92e8a9484d483837abc38217432bfdfc29896aece53e7c
148 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file contains embedded JavaScript that is heavily obfuscated but contains calls to eval(), indicating it is designed to execute arbitrary code. The ML classifier and PDF JavaScript exploit cluster heuristics strongly suggest malicious intent. The script's primary function appears to be downloading and executing a secondary payload, as is common in exploit-based PDF attacks.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
2093a2058f23d8a1080cf9d3d1c569b15485405c4a8d640c44b07e38e4a44ae2
pdf-javascript-stream PDF /JS object 7 at offset 0x248 8247 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).