Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8ebd6fa09abc3ce…

MALICIOUS

PDF

7.3 KB Created: 2008-31-20 53:85:00 Authoring application: Scribus 1.3.3.12 (via Scribus PDF Library 1.3.3.12)
MD5: 057e3b83209c6ee7101c90a18b61e6a5 SHA-1: 4caa6dbd990b00dad61089f89eab0293f8e1ab44 SHA-256: c8ebd6fa09abc3ce89dc1ca4e9289e1c9e3ba8e2298065ed87407819fd5c9d1c
88 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1059.007 JavaScript

The PDF contains embedded JavaScript with multiple eval() calls, indicating obfuscation and malicious intent. The ML classifier strongly flagged this sample as malicious. The JavaScript appears to be constructing a string via concatenation and eval, likely to download and execute a second-stage payload. The presence of 'Scribus' in the metadata is likely a decoy.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0013_001.js
d551c23262f2640c3dbdf3b7548ab6d810c9be28edc207e17bf81b1ab304a59d
pdf-javascript-stream PDF /JS object 13 at offset 0x38B 5960 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 5 eval/decoder/string-building token(s).