Malicious PDF — malware analysis report

Static analysis result for SHA-256 9cc7d1433e30f5d0…

MALICIOUS

PDF

25.8 KB Created: 2006-02-01 14:14:12 Authoring application: Wegoptyr (via HghTc6Fs)
MD5: 2abc857d01bd14a587d60a251e069271 SHA-1: 9d3f2e8c9c66f679b8dadc1d0a3f469336b4a69e SHA-256: 9cc7d1433e30f5d0fcbaa0377934b612f6b3499632088be0c563ad79423d329b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1027 Obfuscated Files or Information

The PDF file contains embedded JavaScript streams, with one heuristic firing indicating an eval() call. The ML classifier strongly flagged this PDF as malicious. The presence of obfuscated JavaScript suggests the intent is to download and execute a secondary payload. No specific family could be identified due to the obfuscation.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
109ea56effe5afdd1851beab5555000b35c19ec312608d02d5da76ef0055d265
pdf-javascript-stream PDF /JS object 7 at offset 0x1EE 25333 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s).
javascript_obj0007_001.js
03c2be298a291ae91fa604fc4e5c34d6b805c7e9c42025887188dbb0ccf8c86e
pdf-javascript-stream PDF /JS object 7 at offset 0x1EE 25058 bytes