Malicious PDF — malware analysis report

Static analysis result for SHA-256 c6c23d214a9e9620…

MALICIOUS

PDF

14.49 MB Created: 2014-03-05 11:50:41 Authoring application: CorelDRAW (via Corel PDF Engine Version 3.0.0.739)
MD5: e7f4fb58946e6f82fb88ee9f14227744 SHA-1: c7e5190952b29fbd9f1a61365bc92d396160c683 SHA-256: c6c23d214a9e96206904f9cc8d9850c8934ed309ee7759c9986f6fd683dc7be9
64 Risk Score

Malware Insights

MITRE ATT&CK
T1553.005 Mark-of-the-Web Bypass

The primary heuristic firing indicates a polyglot PDF, meaning it contains a secondary embedded PDF with suspicious static findings. This strongly suggests the embedded PDF is designed to exploit vulnerabilities or deliver malicious content. The file itself is a PDF, and the presence of an embedded PDF is a common delivery mechanism for exploits targeting PDF readers. No document body or script content was available for further analysis.

Machine Learning

  • Nyx PDF Classifier clean score 0.0613

Heuristics 2

  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_012_off004c5923.bin
8c2116392516537e96d4c3bbdece1c7dd43e8a7d3395df25d40517c5a6555966
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4C5923 19497 bytes
polyglot_child_pdf_off004ccfc3.pdf
0fe86a090a11c40db552ee2ca231d8f06ced56de1a0c4ef2dfefd3f15345b512
polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x4CCFC3 8388608 bytes