Malicious PDF — malware analysis report

Static analysis result for SHA-256 ac5cb3f12d47039d…

MALICIOUS

PDF

20.2 KB
MD5: 05e1ec739f2a17f0aa99a2a75d5a98ad SHA-1: 6298b1521a6a27db8079a7545c10840aae567eed SHA-256: ac5cb3f12d47039d270207138a3496eb561723bd407d06c9bab8b90053b9c14c
196 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1559.002 Component Object Model Hijacking

The sample is a PDF file flagged by ClamAV as Win.Exploit.CVE_2018_4990-6599478-0. High-severity heuristics indicate JPXDecode with active content and a malformed JPEG2000 box structure, strongly suggesting exploitation of CVE-2018-4990. The ML classifier also returned a high probability of maliciousness. No scripts were extracted, but the PDF structure itself indicates an exploit attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 7

  • JPXDecode + active content — JPEG2000 CVE-family indicator high CVE related PDF_JPX_CVE_2018_4990_RELATED
    PDF uses /JPXDecode (JPEG2000) alongside JavaScript, XFA, or RichMedia indicators. This matches the delivery pattern for Adobe Reader JPEG2000 parser exploit families, including CVE-2018-4990, but does not prove the exact malformed JP2/JPX primitive.
  • Malformed JPEG2000/JP2 box structure high CVE related PDF_JP2_BOX_ANOMALY
    PDF embeds JPEG2000/JP2 data with malformed box sizes. This is a parser-exploit indicator for JPX/JPEG2000 CVE families, not a unique CVE fingerprint.
  • ClamAV: Win.Exploit.CVE_2018_4990-6599478-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Exploit.CVE_2018_4990-6599478-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 1 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_cff_off0000476b.bin
3ad89875e6fb7800b92b2a7d51b20b4698616ec3f17bd584488b4745cd64e011
pdf-font-stream PDF embedded font (cff) at offset 0x476B 1578 bytes