Malicious PDF — malware analysis report

Static analysis result for SHA-256 62d24763396e9400…

MALICIOUS

PDF

7.1 KB
MD5: f028db99131b5f2b1b8af15cd67c6af5 SHA-1: 10ae7dc36af560c1f909e42f6eff0099294cbdf3 SHA-256: 62d24763396e9400d09a6933846172c517d161aeb14ccdc3f55a81132cc2c95c
150 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript that utilizes the `unescape()` function, a common indicator of exploit code. This JavaScript is likely designed to download and execute a secondary payload, as suggested by the 'PDF JavaScript exploit cluster' heuristic. The benign URLs found are not indicative of malicious activity, and no document body text was available for further analysis.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9825

Heuristics 6

  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00000327.bin
e03ed540da4b9372a21483e09ff13f7c0f176f998f3acf3e103125a10c394733
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x327 2323 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
stream_003_off00000829.bin
29b0fca95eeb8a4e8e189bed1e35b63a00aeaa515c2e8734c5f09619d7499e4c
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x829 442 bytes