Malicious PDF — malware analysis report

Static analysis result for SHA-256 5ae143002bc913b6…

MALICIOUS

PDF

7.2 KB
MD5: 17f5751b266cfffd698cb4aa27fe2317 SHA-1: 77d299a85d93201e54a29576d197e6169c74aaf7 SHA-256: 5ae143002bc913b6b52ffad98ce5dfcdc1eb0454c944b2374fad1a300d13739d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution

This PDF file contains embedded JavaScript and a Flash object, both of which are flagged as suspicious. The JavaScript appears to be obfuscated and is designed to execute the embedded Flash exploit. The ML classifier strongly indicates maliciousness, suggesting the primary goal is to exploit a client vulnerability.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
exploit.swf
49b04eca9be01c285a55c8ebf6d33b686ebd88925f5f524951dc74928b300173
pdf-embedded-file PDF EmbeddedFile object 14 at offset 0x48C 3764 bytes
javascript_obj0017_000.js
caddadbdd829e2e88f26a957b839b61b7e9200708ff477d3a94cbfea2ec48791
pdf-javascript-stream PDF /JS object 17 at offset 0x13F4 113 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).
javascript_obj0017_001.js
7e219adcb47b4d4625733e71f477581b6000501c13149755274ffb3d3c014bf9
pdf-javascript-stream PDF /JS object 17 at offset 0x13F4 57 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).