Malicious PDF — malware analysis report

Static analysis result for SHA-256 c06fcdd5827a71cc…

MALICIOUS

PDF

7.1 KB
MD5: deb0815b7c2ff35c2e33379b8f5520f7 SHA-1: 22613d08d917567f0b33935ee055a7c3bc325d77 SHA-256: c06fcdd5827a71ccad238996f629bc07fdccf69b0b9ff1a68934390d5318a270
88 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings including 'PDF_JAVASCRIPT' and 'PDF_JS'. The 'PDF_UNESCAPE' heuristic suggests obfuscation techniques were used within the script. The ML classifier also flagged this PDF as malicious with high confidence. While no specific URLs or further script content were extracted, the presence of obfuscated JavaScript strongly suggests an attempt to exploit vulnerabilities or deliver a malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9825

Heuristics 5

  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00000327.bin
7d6309498777105d0ac6ee2c25760fef085bbf486d39d87574fc161f5762203f
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x327 2970 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
stream_003_off00000846.bin
edaadbc6965f5c963974255104d6bc35c8b77ed2b68cee610eb38cca3f33dae6
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x846 442 bytes