Malicious PDF / .TMP — malware analysis report

Static analysis result for SHA-256 0e172212f99fe13e…

MALICIOUS

PDF / .TMP

1.95 MB
MD5: c32792d2459fae9530dbd4b80498b81a SHA-1: 3205e838d9e419e1af787e33c883e86fb7f2b6a1 SHA-256: 0e172212f99fe13e82123fa0745b18817183622fd890bf8e0119a52919b56a93
206 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript that utilizes eval() and is flagged as part of an exploit cluster. This indicates the script is designed to execute malicious code, likely downloading a second-stage payload. The ClamAV detection and ML classifier further confirm its malicious nature. No specific family could be identified due to the obfuscated nature of the script.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • ClamAV: Pdf.Exploit.Agent-21090 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-21090
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0032_000.js
d59e4397008235fb1ff6aedb03f8064335762770f41e5c92003507a5e8be09fc
pdf-javascript-stream PDF /JS object 32 at offset 0x2CA 3073373 bytes