Malicious PDF — malware analysis report

Static analysis result for SHA-256 50d9d4906aba581f…

MALICIOUS

PDF

47.6 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: Acrobat PDFMaker 7.0.5 for PowerPoint (via subst)
MD5: 0db3afea1bbb3b62b268e6382864caaa SHA-1: 028245f2ca8c95ad6ff09bf82a2457edc25eaf9c SHA-256: 50d9d4906aba581fb428c517fa50ec29f5a7e0903c99c06187b0ccfce3edd6c6
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The critical ClamAV detection and high ML classifier score indicate malicious intent. The PDF contains embedded JavaScript, which is a common technique for exploiting vulnerabilities and delivering further malware. The JavaScript action and embedded JS stream heuristics confirm the presence and execution of this script. The file is identified as Pdf.Exploit.Dropped-94, suggesting it's a dropper for other malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
c22fd7cdfe8d4956803728c10f39ca20abd6ff34925082f8711ddaa08b9a0658
pdf-javascript-stream PDF /JS object 76 at offset 0x99B 45977 bytes