Malicious PDF — malware analysis report

Static analysis result for SHA-256 ac5ff7efb066885f…

MALICIOUS

PDF

47.1 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: Acrobat PDFMaker 7.0.5 for PowerPoint (via subst)
MD5: 858a274ecf572490cd92ebe2d7e7267a SHA-1: 04a52df97f0dd6c42ad3942f2e40e85c29007710 SHA-256: ac5ff7efb066885fdb7c0ba427bef8df176f4ba8a96d8d886734fdafedde6418
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by heuristic firings for PDF_JAVASCRIPT and PDF_JS. ClamAV detection as Pdf.Exploit.Dropped-94 further confirms its malicious nature. The embedded JavaScript, which is a large stream, is likely responsible for executing the exploit. The file's SHA256 hash is included as a primary IOC.

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
eb16152a9f58cc6717be5066c68717cec34699d614e581cea0fe9aa2bb5923c4
pdf-javascript-stream PDF /JS object 76 at offset 0x99B 45426 bytes