Malicious PDF — malware analysis report

Static analysis result for SHA-256 393ceb03d89434eb…

MALICIOUS

PDF

47.2 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: Acrobat PDFMaker 7.0.5 for PowerPoint (via substr)
MD5: 1458296f351b4b7a35bebac92ebd6a94 SHA-1: 5e59dca6e85786f35cf56c8acfa447633e612fe4 SHA-256: 393ceb03d89434eb85b28e55f65bea1419883bf31faede990f6fe106b27c721a
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The file is identified as malicious by ClamAV with the signature Pdf.Exploit.Dropped-94. Static analysis detected embedded JavaScript, indicating an attempt to execute malicious code upon opening the PDF. The ML classifier also strongly flagged this PDF as malicious. The document body appears to be metadata and not user-facing content, suggesting the exploit is the primary function.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
a3628f1da7c0d6d39c8d207e71c2bc53dddd7d788d261bb34a6057ad706dd284
pdf-javascript-stream PDF /JS object 76 at offset 0xB968 533 bytes