Malicious PDF — malware analysis report

Static analysis result for SHA-256 44f342fc19497725…

MALICIOUS

PDF

1.9 KB Authoring application: sli
MD5: e65e4a05c40fbb3aa21f512857d02646 SHA-1: 1ab4738fb557e9e80f83955837e94566c287e293 SHA-256: 44f342fc194977252ac021120a36325bb81a746e118d4a9460c8e2a62d9ade03
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

This PDF was flagged as malicious by multiple engines, including ClamAV which identified it as Pdf.Exploit.Dropped-91. Embedded JavaScript was detected, indicating the file likely attempts to exploit a vulnerability within the PDF reader to download and execute a second-stage payload. The ML classifier also provided a very high confidence score for maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-91 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-91
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
5149cd477214b805b3146603b81ab01b4d439ee714b5c154add836671c77be8f
pdf-javascript-stream PDF /JS object 76 at offset 0x426 548 bytes
deobfuscated.js
1935c7c0e56f278076b9e870331873c23c3530fa73c2fe1cf6780207423b16a9
deobfuscated-js PDF JavaScript deobfuscation pass 1213 bytes