Malicious PDF — malware analysis report

Static analysis result for SHA-256 be0a552cf48e4abf…

MALICIOUS

PDF

809.3 KB
MD5: 37a9c45b78f4dee9da8fd8019f66005a SHA-1: 28575e005666e31419ecbfa6a65699c96f1d0568 SHA-256: be0a552cf48e4abf95678e14b63e4c0d334034294252629173493167702cdd60
114 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The critical ClamAV detection and the ML classifier strongly indicate malicious intent. The presence of embedded JavaScript, identified by heuristic firings, suggests the PDF is designed to act as a dropper. This JavaScript is likely responsible for downloading and executing a second-stage payload, which is a common technique for malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7142700-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7142700-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off0006d90c.js
dcefc16710d335e69f60cdd8a0e174d43939d02eaa8dd4c6d7ce4ca63f06495b
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6D90C 289498 bytes