Malicious PDF / .TMP — malware analysis report

Static analysis result for SHA-256 6502a77d107e8c42…

MALICIOUS

PDF / .TMP

1.95 MB
MD5: ee6c28185158ebffcc3da0918362d46e SHA-1: 3a1681f0c92b695583610106e549bdbd370e6dde SHA-256: 6502a77d107e8c422a99ea02d74f546e6fa2e1572683523b36e7d6d42c0a8b15
146 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings including 'PDF_JAVASCRIPT', 'PDF_JS', and 'PDF_EVAL'. The 'PDF_JS_EXPLOIT_CLUSTER' and high ML confidence suggest this JavaScript is malicious and likely exploits a vulnerability to achieve code execution. The script itself, while heavily obfuscated and truncated, is identified as 'javascript_obj0032_000.js', and its primary function is presumed to be downloading and executing a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0032_000.js
b05672e51d7ca0238cd04aa68e053e7eb51d5dbe211e0314c1a8ef2c7481665f
pdf-javascript-stream PDF /JS object 32 at offset 0x2CA 2789514 bytes