Malicious PDF — malware analysis report

Static analysis result for SHA-256 c75a115d315d689a…

MALICIOUS

PDF

1.1 KB Created: 2010-09-06 14:20:33 Authoring application: FPDF 1.6
MD5: 2fba257dd3e894d77cf6703a1ee5b44f SHA-1: 3a6e4478e936685c4eacf7824be98567fafff4ff SHA-256: c75a115d315d689ab1cd4f082c86155b19a0bd5d1fc82d2019d628e284127daf
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The ML classifier and correlated signals strongly suggest malicious intent. The embedded JavaScript is likely designed to exploit a vulnerability within the PDF reader to download and execute a secondary payload. The authoring application 'FPDF 1.6' is noted as an indicator.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Correlated malicious PDF JavaScript signals critical PDF_CORRELATED_MALICIOUS_JS
    PDF JavaScript or auto-action content is corroborated by exploit staging, ML, or suspicious extracted-artifact findings. This correlation promotes old exploit-kit PDFs that otherwise remain in the suspicious band because each individual signal is intentionally weighted conservatively.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.