Malicious PDF — malware analysis report

Static analysis result for SHA-256 b35e17c703e2b164…

MALICIOUS

PDF

1.95 MB Created: 2011-72-51 03:25:00
MD5: cbaca7b1c052b8a53f200b22651d3abe SHA-1: 27a2850bc475ae21982234036cf482b6d3a80efc SHA-256: b35e17c703e2b164dbfcfc6009d3a1020b2897f545f7e97b89f201da850cc8ae
88 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 Command and Scripting Interpreter: PowerShell T1204.002 Malicious File: Malicious JavaScript

The PDF contains embedded JavaScript, which is flagged by multiple heuristics including a high-confidence ML classifier. The JavaScript stream is obfuscated and uses an eval() call, indicating it is designed to execute arbitrary code. The primary attack pattern is likely to exploit vulnerabilities or deliver a secondary payload via this script.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0001_000.js
cc1ccb7a1b451fecf2ce6b413628c5d874a1efd22ea431aafd2efc34211c1408
pdf-javascript-stream PDF /JS object 1 at offset 0x61C0 541 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).