Malicious PDF — malware analysis report

Static analysis result for SHA-256 afdd485b76afb72d…

MALICIOUS

PDF

496.1 KB Created: 2007-10-30 16:52:01 UTC Authoring application: Adobe PDF Library 6.1
MD5: eab40da7423652586fc0c14c9f72a67f SHA-1: ccc32bcfa2b4e822a22c7c5f7835e2a1e1557882 SHA-256: afdd485b76afb72d34e6d35593f7ef2f70f33a551ac4febbd03723f773e914b3
66 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The ML classifier also flagged this PDF as malicious. While no specific malicious URLs were extracted, the presence of JavaScript and the ML detection strongly suggest an attempt to execute malicious code, likely for downloading further payloads or exploiting vulnerabilities. The PDF_FILTER_HEX heuristic with exploit indicators further supports this.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6062

Heuristics 4

  • ASCIIHexDecode filter (with exploit indicators) medium PDF_FILTER_HEX
    Hex-encoding filter present alongside exploit delivery indicators — often used to hide payload or shellcode bytes
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/pdfx/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0137_000.js
a34e040c1d1de9753841e902f5753a50f2f20c2bf9fc3467fac88d9de5a2ffc5
pdf-javascript-stream PDF /JS object 137 at offset 0x5B2F 159 bytes
stream_016_off00016f48.bin
6b6ef3ac1e9a08d374d938f7197fdb37384ba51bc787948a161c6bb432541c0c
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x16F48 61976 bytes
stream_084_off00071c33.bin
c27f10b42177531e9bd82b24cf0c4f697cb25e3079429d5c4d936a1a174f2a9c
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x71C33 36716 bytes
icc_00_off00004e0b.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x4E0B 3144 bytes
font_00_sfnt_off0006cb94.bin
2162f340d7c4c73e8859a418471a07e84250ead106fa20a0232ddb5f60b51a18
pdf-font-stream PDF embedded font (sfnt) at offset 0x6CB94 29312 bytes