Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ea6cddf6f7227e5…

MALICIOUS

PDF

47.6 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: Acrobat PDFMaker 7.0.5 for PowerPoint (via subst)
MD5: 71141b3ea56c25058aefe8f7f08704d8 SHA-1: dff2d9421c2439c6800f9cb26b8532ade71e1e4c SHA-256: 3ea6cddf6f7227e52e0ce461430120f333005a9d7d6dbbe95f9fd49de27b40d1
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was detected as malicious by ClamAV with the signature Pdf.Exploit.Dropped-94, indicating it contains an exploit. The presence of JavaScript actions and embedded JS streams further supports this, suggesting the file is designed to execute malicious code upon opening. The embedded JavaScript is likely responsible for downloading and executing a second-stage payload.

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
d743dae2449b891828d41cf6e765ce5db1ba2f5c5fca46e5aabcd82d5c31da51
pdf-javascript-stream PDF /JS object 76 at offset 0x99B 45965 bytes