Malicious PDF — malware analysis report

Static analysis result for SHA-256 898822fa7bb6eebb…

MALICIOUS

PDF

50.5 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: Acrobat PDFMaker 7.0.5 for PowerPoint (via subst)
MD5: 164b1aa8427e63be799368a223e11da5 SHA-1: 9a4bca396ae4236498e6731df1d4e8f34183d33d SHA-256: 898822fa7bb6eebb304eb270cee771faf27d28e9a2036ef559a6e971e07cd964
106 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is identified as a malicious PDF by ClamAV (Pdf.Exploit.Dropped-94) and a machine learning classifier. Heuristics indicate the presence of JavaScript actions and embedded JS streams, suggesting the PDF is designed to execute malicious code. The large embedded JavaScript object likely contains exploit code or a downloader for a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
3979a72c9f4a042298acdefc8e7f700d81315986fe99f2598356421ed854599e
pdf-javascript-stream PDF /JS object 76 at offset 0x99B 48987 bytes