Malicious PDF — malware analysis report

Static analysis result for SHA-256 62e3c4018e89f54a…

MALICIOUS

PDF

18.0 KB Created: 2011-72-51 03:25:00 Authoring application: String.fromCharCode
MD5: f6601580e825d7d88ea4ca9c6a666ded SHA-1: 65a1374569816ebd34b7ce59b1c15407cce492ea SHA-256: 62e3c4018e89f54a995f050ba90c9ea986ce315af77eb8961dbadec748185da1
114 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript that is obfuscated using String.fromCharCode and other string manipulation techniques. The script appears to download and execute a second-stage payload from a remote source, as indicated by the critical heuristic firing for a PDF JavaScript exploit cluster. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • String.fromCharCode low PDF_FROMCHARCODE
    String.fromCharCode found — used to construct payload strings dynamically. Common in benign JavaScript libraries for codepoint manipulation, so this alone is informational; weaponised use is also caught by the dedicated fromCharCode-stage and exploit-shape rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0001_000.js
db1592572452e631c2fb2400f63a5ed5e1b8ac658f38b3ed77f1b1fa8d6f1531
pdf-javascript-stream PDF /JS object 1 at offset 0x45F1 337 bytes