Malicious PDF — malware analysis report

Static analysis result for SHA-256 4022fae4cb43a000…

MALICIOUS

PDF

12.7 KB
MD5: d4ba90d816ef48f0d748074d400dbbcd SHA-1: be7c4bf8e3b88d05873507bf2fc0a2d7c7121567 SHA-256: 4022fae4cb43a000b13aa9453e0abc182ba32a5a1da564c498e6e11da21ebad3
146 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

This PDF file was flagged as malicious by a machine learning classifier and ClamAV with the signature Pdf.Exploit.Dropped-94. Static analysis revealed embedded JavaScript, including a metadata eval stager, indicating an attempt to execute arbitrary code. The primary function appears to be downloading and executing a second-stage payload, typical of dropper malware.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • PDF metadata JavaScript eval stager high PDF_METADATA_EVAL_STAGER
    PDF JavaScript reads document metadata fields such as title, subject, or producer, decodes character data with parseInt/String.fromCharCode style helpers, and evals the recovered stage. This is a high-signal exploit-kit staging pattern.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
7b37574e63c38690527896ad84831f313745f465d284e22ba09869c83808fae2
pdf-javascript-stream PDF /JS object 76 at offset 0x3094 331 bytes