Malicious PDF — malware analysis report

Static analysis result for SHA-256 2439419fe7a396cd…

MALICIOUS

PDF

69.5 KB
MD5: 4ec735d3eb5a585dba588e0baabad8ea SHA-1: 36eeb9c3bdc06616280dbc498376052872f0b6d2 SHA-256: 2439419fe7a396cd8728dc3996f6de71e6ea07a2b3dcdc7dfa5b06df19308c75
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1055.012 Process Injection: Process Hollowing

The PDF document contains a Base64-encoded Windows executable payload. The heuristic indicates that this payload is likely intended for process injection, utilizing APIs such as VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread. The embedded executable's SHA256 hash is identified as a primary indicator of compromise.

Heuristics 1

  • Base64-encoded Windows executable payload in PDF critical PDF_BASE64_PE_PAYLOAD
    PDF text contains a long base64 blob that decodes to a verified Windows PE executable. This catches payloads hidden after EOF, inside comments, or in plain text outside normal PDF streams.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
base64_pdf_pe_000002fe.exe
cac25a0c85ff0522a7105b86ac53326b6c5a8b9031d9ab76d5f39249c561bd20
embedded-pe PDF raw base64 PE payload at offset 0x2FE 52736 bytes