Malicious PDF — malware analysis report

Static analysis result for SHA-256 cefaf2afea874645…

MALICIOUS

PDF

12.4 KB
MD5: 02d330276697a42993ea8d5c21e05f83 SHA-1: 7387ebf0fe137cfdc9dc782430436bd159172aef SHA-256: cefaf2afea874645a969c1948e5e438da649caa9d18f9131cc34bb7e7acbef88
106 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious File

The PDF sample was flagged as malicious by a machine learning classifier and ClamAV, with the latter identifying it as Pdf.Exploit.Pdfka-9. Heuristics indicate the presence of embedded JavaScript, which is a common technique for exploiting PDF vulnerabilities to download and execute further malicious content. No document body or specific script content was available for analysis, but the combination of heuristics and exploit detection strongly suggests a malicious PDF dropper.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
0260c15b69c20b47fd7b321dad7713a442c89159ccb2421c11231173bf6c22d4
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11581 bytes
Detection
ClamAV: Pdf.Exploit.Pdfka-9
Obfuscation or payload: unlikely