MALICIOUS
100
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
The PDF file contains a Base64-encoded PE payload, which is a strong indicator of malicious intent. The payload is likely designed to be decoded and executed using process injection techniques, as suggested by the presence of APIs like VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread. The ML classifier also strongly flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 0.9952
Heuristics 1
-
Base64-encoded Windows executable payload in PDF critical PDF_BASE64_PE_PAYLOADPDF text contains a long base64 blob that decodes to a verified Windows PE executable. This catches payloads hidden after EOF, inside comments, or in plain text outside normal PDF streams.
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
base64_pdf_pe_000002fe.execac25a0c85ff0522a7105b86ac53326b6c5a8b9031d9ab76d5f39249c561bd20 |
embedded-pe | PDF raw base64 PE payload at offset 0x2FE | 52736 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.