MALICIOUS
130
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.9959
Heuristics 2
-
Base64-encoded Windows executable payload in PDF critical PDF_BASE64_PE_PAYLOADPDF text contains a long base64 blob that decodes to a verified Windows PE executable. This catches payloads hidden after EOF, inside comments, or in plain text outside normal PDF streams.
-
Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
base64_pdf_pe_00000284.exe |
embedded-pe | PDF raw base64 PE payload at offset 0x284 | 52736 bytes |
SHA-256: d669e8c36fcacaed05479f863c7b6ac25bc8f859f1e8f4ba911bf37147976131 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
actual_type=PE; declared_or_context_type=PDF; filename=base64_pdf_pe_00000284.exe; kind=embedded-pe Static shellcode analysis found candidate code region(s). Indicators: SC_PUSH_STRING, SC_STR_VIRTUALALLOC, SC_STR_POWERSHELL Static shellcode analysis recovered API/import strings: VirtualAlloc, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, OpenProcess Static shellcode analysis recovered command string(s): PowerShell
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.