Malicious PDF — malware analysis report

Static analysis result for SHA-256 a141147b161e4070…

MALICIOUS

PDF

4.4 KB Created: 2010-04-23 06:59:32 Authoring application: Dakmiyfomimaba
MD5: 9fefd505295ff05fb90113b3f0916aa0 SHA-1: 257adf03d007d4e4a99aa65e656b8ce58804fa44 SHA-256: a141147b161e4070e9f87736f68f049cc0e7521e0d2286083d9a407cc312c4e0
86 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF contains embedded JavaScript, flagged by multiple heuristics as malicious. The 'PDF_PAGE_WORD_XOR_EVAL_STAGER' heuristic indicates the script is designed to launch a second-stage payload. The ML classifier strongly supports the malicious nature of this PDF. No specific family could be identified, and no direct IOCs like URLs or hashes were extracted from the script content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Page-word XOR JavaScript eval stager high PDF_PAGE_WORD_XOR_EVAL_STAGER
    PDF JavaScript enumerates rendered page words with getPageNthWord/getPageNumWords, extracts encoded byte fragments, XOR-decodes the stage with char-code helpers, and evals the result. This is an old exploit-kit staging pattern and is not normal document JavaScript.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0010_000.js
77692aa6eee912f470430c71119e8b9c8ba346a577cd63ae147470c7ef4ca3c3
pdf-javascript-stream PDF /JS object 10 at offset 0xC9D 896 bytes