Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a256fe6c8ce9452…

MALICIOUS

PDF

22.0 KB Created: 2000-05-09 22:28:06 Authoring application: FrameMaker+SGML 6.0: AdobePS 8.5.1 (via Acrobat Distiller 4.0 for Macintosh)
MD5: 6d0258216ff8ee9ee2635bad2dc88d7d SHA-1: 6bc94f998c49ff90af8eee576c4097e91599dcd3 SHA-256: 0a256fe6c8ce9452714d03188875f63da1231d4410255cf4be4ecaabd8ba19fc
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains an embedded JavaScript payload that attempts to execute further commands. The document also contains heuristics indicating a lure to execute commands via the clipboard, likely to run the embedded script. The script itself appears to be a downloader or dropper, as evidenced by its structure and the registry read for script settings, suggesting it prepares for further execution.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4951

Heuristics 4

  • Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.
  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.skyi-
    • http://www.mirc.com

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00001b9e.bin
e73ed089b5f202e2fefba867116861f109e59914e20ac39407e5a8ffd360714a
pdf-embedded-script PDF decompressed stream script payload at offset 0x1B9E 2746 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s).