Malicious PDF — malware analysis report

Static analysis result for SHA-256 0bb3a1208d758695…

MALICIOUS

PDF

69.5 KB
MD5: a62bf8dc352afb43f03ec26f98d51a24 SHA-1: d60142ab473c502b2a7b11775cbbaefd186a3926 SHA-256: 0bb3a1208d758695dd099f0eb64f34e19f56010afeb7a8ca7a533301daca6230
100 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1055.012 Process Injection

A critical heuristic identified a Base64-encoded Windows executable payload embedded within the PDF. The payload's characteristics suggest it is designed for process injection, utilizing APIs like VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread. The embedded executable's SHA256 hash is also provided as an IOC.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9952

Heuristics 1

  • Base64-encoded Windows executable payload in PDF critical PDF_BASE64_PE_PAYLOAD
    PDF text contains a long base64 blob that decodes to a verified Windows PE executable. This catches payloads hidden after EOF, inside comments, or in plain text outside normal PDF streams.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
base64_pdf_pe_000002fe.exe
cac25a0c85ff0522a7105b86ac53326b6c5a8b9031d9ab76d5f39249c561bd20
embedded-pe PDF raw base64 PE payload at offset 0x2FE 52736 bytes