Malicious PDF — malware analysis report

Static analysis result for SHA-256 71763368037c5dc9…

MALICIOUS

PDF

7.0 KB
MD5: cbcafea90f712296d6f38bcdca0ede43 SHA-1: 1495975fda17a39347bdf833f6d9d7fc3e2786c9 SHA-256: 71763368037c5dc996285617e6a41a32c5390cb8228277cbdcedf0d35db614c2
150 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file contains embedded JavaScript that is obfuscated and utilizes an unescape function, indicating an attempt to exploit a vulnerability. The ML classifier strongly flags this as malicious. The primary function of the embedded JavaScript appears to be the execution of further malicious code, likely downloaded from an external source, which is a common technique for delivering secondary payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9825

Heuristics 5

  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00000327.bin
1e05931d008d9e6efe20ae3730a451452d788a87a22be8b39dea35121c83e5b9
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x327 2289 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
stream_003_off00000811.bin
fc2a91e3102876710ac8c3a6ad27b284bc666b425a831dde7a2bf18b06a6b7da
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x811 442 bytes