Malicious PDF — malware analysis report

Static analysis result for SHA-256 216aaece21a65588…

MALICIOUS

PDF

281.3 KB
MD5: dbb6b5100686a7e2e8e9380f8b43657a SHA-1: 97b74a8dd361d7d0485f744792863c41e95e99ab SHA-256: 216aaece21a65588ceadfb5a486bbb338278438a0c7ebf836c00bc51a34d7294
90 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.001 PowerShell

The PDF file was detected by ClamAV as 'Pdf.Exploit.Agent-22400', indicating it contains an exploit. The presence of numerous streams and the use of String.fromCharCode suggest obfuscation techniques common in exploit delivery. While no specific script was directly executed, the structure and ClamAV signature point towards a malicious PDF designed to exploit a vulnerability and likely download a secondary payload.

Machine Learning

  • Nyx PDF Classifier clean score 0.0047

Heuristics 5

  • ClamAV: Pdf.Exploit.Agent-22400 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-22400
  • Unusually high stream count medium PDF_MANY_STREAMS
    PDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
  • String.fromCharCode low PDF_FROMCHARCODE
    String.fromCharCode found — used to construct payload strings dynamically. Common in benign JavaScript libraries for codepoint manipulation, so this alone is informational; weaponised use is also caught by the dedicated fromCharCode-stage and exploit-shape rules. (matched inside decoded stream)
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/pdfx/1.3/In PDF document text
    • http://ns.adobe.com/AcrobatAdhocWorkflow/1.0/In PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off0000399f.js
07e868d2b36371bc69cf41cfc852608cf7198889bee400841b199a4c50f1580d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x399F 10491 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s).
stream_003_off00004632.js
462f13116e40be82cd05b58eb6f642bc46c10bb4760f29ca21c7ee8ee79b0f21
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4632 2673 bytes
objstm_1315_00.bin
17d0a7604bbff05b8c2d4c04d27f710944d6fa09ad7551b5a702154a906644b8
pdf-objstm-decoded PDF /ObjStm 1315 0 obj (inflated) 19264 bytes
objstm_1316_00.bin
f02b2015cf9b4db36f996f6f1d786dda71977ddfa5f8de4dd6a9f3e0ec9ad7ac
pdf-objstm-decoded PDF /ObjStm 1316 0 obj (inflated) 28112 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
objstm_1317_00.bin
293b0d3f680f4641250f03fa4ccc67832149ad9d1da4cdd570634058d3d293b7
pdf-objstm-decoded PDF /ObjStm 1317 0 obj (inflated) 22486 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).