Malicious PDF — malware analysis report

Static analysis result for SHA-256 a8e8b68802dfda51…

MALICIOUS

PDF

2.8 KB
MD5: def9fee1b4fedb34108daec7d0009863 SHA-1: 32340bdf2340d17d17ac212b7a7709f5dcbec75c SHA-256: a8e8b68802dfda510340107d4c7465277b310e699c173f647c4fb87b44d52aff
96 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF document contains embedded JavaScript, with heuristics indicating the use of eval() and String.fromCharCode(). These techniques are often used to obfuscate and execute malicious code. The ML classifier strongly flagged this PDF as malicious. The embedded JavaScript streams, javascript_obj111611_000.js and javascript_obj111612_001.js, are likely responsible for the malicious behavior, potentially downloading and executing a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • String.fromCharCode low PDF_FROMCHARCODE
    String.fromCharCode found — used to construct payload strings dynamically. Common in benign JavaScript libraries for codepoint manipulation, so this alone is informational; weaponised use is also caught by the dedicated fromCharCode-stage and exploit-shape rules. (matched inside decoded stream)
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj111611_000.js
5e0673098ea0731dd05e46311ac9f6ba85d2efd5252de1c709d07e47d69e418a
pdf-javascript-stream PDF /JS object 111611 at offset 0x197 257 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).
javascript_obj111612_001.js
5f0f364af8fdf4245ebebe2a86110619f78eaa2e35d1217e4f167a2e6a824d5b
pdf-javascript-stream PDF /JS object 111612 at offset 0x267 3367 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).