Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3fa3cec25570c24…

MALICIOUS

PDF

48.7 KB
MD5: f41d8704150244b51f8b150f8c999887 SHA-1: 1cc2a36ec7980be498daeb779d7f8bf524a5f94a SHA-256: b3fa3cec25570c2495e1cbff017b3ed0b430980993ad16ff46b43f847662bd2f
74 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF contains embedded JavaScript and triggers heuristics related to JavaScript actions and exploit indicators. The ML classifier strongly flags this PDF as malicious. The embedded JavaScript is the primary mechanism for delivering the malicious payload, likely by downloading and executing further stages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ASCIIHexDecode filter (with exploit indicators) medium PDF_FILTER_HEX
    Hex-encoding filter present alongside exploit delivery indicators — often used to hide payload or shellcode bytes
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
e54b7d01240f66c3abac6156ce583811ecf5a8a570afe5af17b68b74c78a98f4
pdf-javascript-stream PDF /JS object 12 at offset 0x9413 849 bytes
stream_002_off00009668.bin
070732b3fbbd20295c5b1a911789c30af5b99ce5e14e004bbedc5acf7f113122
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x9668 449 bytes
font_00_sfnt_off00000349.bin
4e56128afad897c8ba22338709048333a61f0c1c8de4785f90267c2edf4d9a4e
pdf-font-stream PDF embedded font (sfnt) at offset 0x349 58553 bytes