Malicious PDF — malware analysis report

Static analysis result for SHA-256 84c2b61051378e01…

MALICIOUS

PDF

1.95 MB Created: 2011-72-51 03:25:00
MD5: 10a20d77a179e5510beba0464b6e831c SHA-1: ec8a0aee05b580d9b670f05f9a3ff77f3a2b2db3 SHA-256: 84c2b61051378e0152d1b69b3766025de0f0b48ba910a354892d262db495d3a5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF contains embedded JavaScript, indicated by PDF_JAVASCRIPT and PDF_JS heuristics. The presence of an eval() call (PDF_EVAL) suggests obfuscated code execution. The ML classifier strongly flags this PDF as malicious. While no specific URLs or commands were extracted, the pattern of embedded JavaScript in a PDF commonly leads to the download and execution of further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9607

Heuristics 6

  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/tiff/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/exif/1.0/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0001_000.js
f963bc9aa8b28a160db694a5e4281d29b1e0a968bfe6b616a9f9b49580dd9907
pdf-javascript-stream PDF /JS object 1 at offset 0x621B 533 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).
icc_00_off000110f6.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x110F6 3144 bytes
font_00_cff_off00011b5b.bin
aa828f1ed1bd0c1309e5cd820e7626c7429316961c7c5f280e740f34c801faca
pdf-font-stream PDF embedded font (cff) at offset 0x11B5B 8143 bytes
font_01_cff_off000136d7.bin
81969d28eeb80b957e1245930ec30696e05a1db8fd79483fb0fbc8ddc908172c
pdf-font-stream PDF embedded font (cff) at offset 0x136D7 8133 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.41, consistent with packed or encrypted content.
font_02_cff_off000151fa.bin
99ed3369cd49fa318d2c208ae06e6e76dc664cd66cb0c4fc6aa7b272a5506e3c
pdf-font-stream PDF embedded font (cff) at offset 0x151FA 11009 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.43, consistent with packed or encrypted content.
font_03_cff_off00017456.bin
dbb969be82f2180cb8eb904017632591d9eb1f43e0ea6982165f284373412a2a
pdf-font-stream PDF embedded font (cff) at offset 0x17456 10398 bytes
font_04_cff_off0001960b.bin
ff9beecbbbe819260d1e4f7976be000ed3302326e4e7f5cdce28cc833aecea33
pdf-font-stream PDF embedded font (cff) at offset 0x1960B 6954 bytes