Malicious PDF — malware analysis report

Static analysis result for SHA-256 c1a2013949aeed9c…

MALICIOUS

PDF

34.0 KB Created: 2010-02-28 19:27:08 +03:00 Authoring application: comesOneWeb (via 523f43693bfa6c607d2fe43b43ba96fd)
MD5: 2be01d659751c5e5bef1e3246c28869a SHA-1: f8f00064df37d67125b92bed386856366187f60f SHA-256: c1a2013949aeed9cf2e37e986d2c5be9eafa611978fd5787865fd7eb542ae060
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF sample contains multiple embedded JavaScript streams, indicated by PDF_JAVASCRIPT and PDF_JS heuristics. The ML classifier also flagged this PDF as malicious with high confidence. The presence of JavaScript actions and potential exploit indicators like ASCII85Decode filter suggests the document is designed to execute malicious code upon opening. The primary attack vector appears to be leveraging JavaScript embedded within the PDF to achieve arbitrary code execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 4

  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85
    ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0018_000.js
edd0c90399fcd3180c705b6b7e82a2c5265864a3bf66269ef98222eb4ee2855d
pdf-javascript-stream PDF /JS object 18 at offset 0x24AA 116 bytes
javascript_obj0020_001.js
48e63fca3f089d4c63a1ec9e2133eb37148fce78f1a0f306ce3b15b694ae68f7
pdf-javascript-stream PDF /JS object 20 at offset 0x25C9 36674 bytes
javascript_obj0022_002.js
b8d555ddbc5747fee6ebf38d6f326c9d9b1f8238a124b6ba2e34f639c3bc4e67
pdf-javascript-stream PDF /JS object 22 at offset 0x818E 78 bytes