Malicious PDF — malware analysis report

Static analysis result for SHA-256 4a4f2786fa01ed74…

MALICIOUS

PDF

326.2 KB Created: 2015-06-05 02:27:53 Authoring application: Joomla! 1.5 - Open Source Content Management (via TCPDF 2.5.000_PHP4 (http://www.tcpdf.org))
MD5: f5d63f5e1be210dc3efb5be29fbb4fcf SHA-1: 8dcf485d172b3a8fc6268a05caca2036d0d5a6eb SHA-256: 4a4f2786fa01ed740eca3a7c9d061c8892f8bfd50171c1a72ae5d870c5365e35
130 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains a high-severity heuristic firing for 'PDF_EVAL', indicating the presence of an eval() call, which is commonly used to execute arbitrary code within PDF documents. Additionally, a critical ClamAV detection identifies it as 'Unix.Trojan.PhpBackdoor-9354530-2'. The ML classifier also flagged it with high confidence. These indicators suggest the PDF is designed to exploit a vulnerability, likely leading to the download and execution of a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9895

Heuristics 2

  • ClamAV: Unix.Trojan.PhpBackdoor-9354530-2 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Unix.Trojan.PhpBackdoor-9354530-2
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000c18f.bin
a5337ef1f5a0dfe4dc8fa6b4f3ef847a53624800b5928a0eeef5b888ceecaabc
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xC18F 264072 bytes