Malicious PDF — malware analysis report

Static analysis result for SHA-256 c247374a6c0fc69e…

MALICIOUS

PDF

326.2 KB Created: 2015-06-05 02:31:47 Authoring application: Joomla! 1.5 - Open Source Content Management (via TCPDF 2.5.000_PHP4 (http://www.tcpdf.org))
MD5: 7b6da5b2aaaad6b175feb51df7bde56a SHA-1: 7a3da77964a46c781f56f5c938848fffa526ed14 SHA-256: c247374a6c0fc69e5789608f747ea84f7b6fff519114a134b0ac4a9a2bfce844
100 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file was detected by ClamAV as Unix.Trojan.PhpBackdoor-9354530-2. Static analysis revealed an eval() call within the PDF structure, indicating potential code execution. The presence of a PHP backdoor suggests an intent to compromise a web server.

Heuristics 2

  • ClamAV: Unix.Trojan.PhpBackdoor-9354530-2 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Unix.Trojan.PhpBackdoor-9354530-2
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000c18f.bin
a5337ef1f5a0dfe4dc8fa6b4f3ef847a53624800b5928a0eeef5b888ceecaabc
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xC18F 264072 bytes