Malicious PDF — malware analysis report

Static analysis result for SHA-256 a4f2672ce65b9faa…

MALICIOUS

PDF

47.1 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: Acrobat PDFMaker 7.0.5 for PowerPoint (via substr)
MD5: 9c0b38b416f24a530c62ab88e8370713 SHA-1: 02e2c020473b6d3d0d3b52e5ff4bc6dd31c3dad2 SHA-256: a4f2672ce65b9faaf4d04a020a0fa05ce5c137a0d4d63cde2fcb64a14ad574fc
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The file is a PDF containing embedded JavaScript, flagged by multiple heuristics and ClamAV as malicious. The ML classifier also strongly indicates maliciousness. The presence of JavaScript actions and streams points to an exploit, likely for dropping a secondary payload as indicated by the ClamAV detection name 'Pdf.Exploit.Dropped-94'. The document body content is not indicative of a specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
dc56fecab9c8b4ab7104713ea0e5c552356fae36ceebd0851267e3151925d457
pdf-javascript-stream PDF /JS object 76 at offset 0xB95A 527 bytes