MALICIOUS
100
Risk Score
Malware Insights
MITRE ATT&CK
T1059 Command and Scripting Interpreter
T1059.001 PowerShell
T1055 Process Injection
T1055.012 Process Hollowing
The PDF file contains a critical heuristic indicating a Base64-encoded Windows executable payload. The payload uses process injection APIs like VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread, suggesting it's designed to inject malicious code into a legitimate process. The decoded PE file has a SHA256 hash of cac25a0c85ff0522a7105b86ac53326b6c5a8b9031d9ab76d5f39249c561bd20.
Machine Learning
- Nyx PDF Classifier malicious score 0.9952
Heuristics 1
-
Base64-encoded Windows executable payload in PDF critical PDF_BASE64_PE_PAYLOADPDF text contains a long base64 blob that decodes to a verified Windows PE executable. This catches payloads hidden after EOF, inside comments, or in plain text outside normal PDF streams.
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
base64_pdf_pe_000002fe.execac25a0c85ff0522a7105b86ac53326b6c5a8b9031d9ab76d5f39249c561bd20 |
embedded-pe | PDF raw base64 PE payload at offset 0x2FE | 52736 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.