Malicious PDF — malware analysis report

Static analysis result for SHA-256 6e0688f730ae86a9…

MALICIOUS

PDF

31.6 KB
MD5: bafb8c32a2d80b9adaf9df0dbeddb52d SHA-1: c294812b3dacda9873fdd5d92b7cb8f0731253f2 SHA-256: 6e0688f730ae86a9b4e57d158744319e8d3e3ad6d074639ae4b6c409183f0110
146 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript with eval() calls, a known technique for executing malicious code. The ML classifier strongly indicates maliciousness. The JavaScript is heavily obfuscated and truncated, making it difficult to determine the exact payload, but the presence of exploit cluster signals suggests it's designed to download and execute a second-stage malicious file. No specific family could be identified.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0032_000.js
98917d8db49ba8a597b00840a35480f12bba8304778ac64b0eff0309b1ff237c
pdf-javascript-stream PDF /JS object 32 at offset 0x2CA 3081941 bytes