Malicious PDF — malware analysis report

Static analysis result for SHA-256 175326bc94f0f221…

MALICIOUS

PDF

3.2 KB
MD5: c9c0e070a224c27aa3e2fbf7b00dc5d6 SHA-1: 95343c7ae5282f3c165f210d837fe0aa4c8af80b SHA-256: 175326bc94f0f2216682392eee2a26533a2dc64d371aeb4c24d9d0cfc81a70e4
206 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript that utilizes the unescape() function, a common indicator of exploit code. The script attempts to call a function with a string derived from the PDF's title, which is likely intended to trigger the exploit. This behavior, combined with critical heuristic firings related to JavaScript exploits and ClamAV detection, strongly suggests the file is malicious and aims to download and execute a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • ClamAV: Pdf.Exploit.Agent-36121 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36121
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
6972ec540f94c8e6e201fe9684e319546ac271c61565f440bd6a27b3032ea1eb
pdf-javascript-stream PDF /JS object 7 at offset 0x9C4 423 bytes