Malicious PDF — malware analysis report

Static analysis result for SHA-256 c292d32c2c25caa4…

MALICIOUS

PDF

47.1 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: Acrobat PDFMaker 7.0.5 for PowerPoint (via substr)
MD5: c3cd18c8d639f9fc39fb42fadb6cb4fb SHA-1: edbce73142ef18b218d8367c8cfaa32877abb6ba SHA-256: c292d32c2c25caa4accc2f59342d12c1cda008789be8091a058f06f54b402eee
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The critical ClamAV detection and high ML classifier score indicate malicious intent. The PDF contains embedded JavaScript, which is a common technique for exploiting vulnerabilities and delivering secondary payloads. The presence of JavaScript actions and embedded JS streams strongly suggests the file is designed to execute code upon opening.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
1bb668802163c9956cb8e100dee6a1fa26bba57f6e10e729ee82f4668511d7db
pdf-javascript-stream PDF /JS object 76 at offset 0x999 45486 bytes