Malicious PDF — malware analysis report

Static analysis result for SHA-256 4f285e12028fbe4e…

MALICIOUS

PDF

82.4 KB Created: 2010-03-17 12:45:11 +01:00
MD5: c0afbca214ab66ba1ebc0ddc8ce49231 SHA-1: 415e108152c72ca7bd61a9b297b793261f979141 SHA-256: 4f285e12028fbe4ed9d8d221418b2d1012df2f9976de1142b787181221ddfe32
130 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The PDF file was flagged as malicious by ClamAV with the signature Win.Trojan.Java-6. Static analysis also identified an embedded file, which was also detected by ClamAV as Win.Trojan.Java-6. The PDF's structure suggests it is image-only, likely serving as a lure to disguise the embedded malicious artifact.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.3458

Heuristics 4

  • ClamAV: Win.Trojan.Java-6 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Java-6
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
Java.ClassLoader.24564.jar.bz2.bz2.bz2.bz2.bz2.bz2
77717e2e87448bc8625b431d9cf0244c44e3228ec4230b8493f9a85465308fa0
pdf-embedded-file PDF EmbeddedFile object 16 at offset 0x1052F 16793 bytes
Detection
ClamAV: Win.Trojan.Java-6
Obfuscation or payload: unlikely