Malicious PDF — malware analysis report

Static analysis result for SHA-256 cc3df7896bfa0ce5…

MALICIOUS

PDF

7.3 KB Created: 2009-12-17 16:59:10 Authoring application: Scribus 1.3.3.12 (via Scribus PDF Library 1.3.3.12)
MD5: e540f8d915b8ab2bd3f98badb42196fd SHA-1: 03a2b2422dfb4668e1ffd60a621ac60b78e00784 SHA-256: cc3df7896bfa0ce5c419c94986361ec600d0c6b4459035d8452c038e14c488a6
128 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged as malicious by an ML classifier with high confidence. Static analysis revealed embedded JavaScript containing eval() and unescape() calls, indicating obfuscation and potential execution of malicious code. The presence of these JavaScript functions strongly suggests an attempt to exploit vulnerabilities or download a secondary payload. No specific family could be identified due to the obfuscation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0021_000.js
49f1536e9e751f07ab8cfe526fd5b274579c7ab6ad51d10397ef94f504edef12
pdf-javascript-stream PDF /JS object 21 at offset 0x1883 536 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s).