Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc2f02d57facee1b…

MALICIOUS

PDF

59.5 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: lice (via ubst)
MD5: 8bc3bd0d339c62e9aa72c889425a066c SHA-1: a570444a9cd361f3ad295e673ad320506df15a6b SHA-256: bc2f02d57facee1b60a0298b17001d44bda66f4f6e92d0eacf5b51805ccb154b
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The file is a PDF document identified as malicious by ClamAV with a critical heuristic firing for PDF exploit. Static analysis detected embedded JavaScript, indicating an attempt to execute code. The presence of JavaScript actions and streams strongly suggests the file is designed to exploit a PDF vulnerability to run malicious scripts, likely for downloading and executing further payloads. The SHA256 hash is included as a primary identifier.

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
e7f01591b790650a590dcda60136b3d43ddbe6e52a36b92c3ad88afdcc0b6fba
pdf-javascript-stream PDF /JS object 76 at offset 0x955 50932 bytes