Malicious PDF — malware analysis report

Static analysis result for SHA-256 d20d8ca1f5e166a0…

MALICIOUS

PDF

59.3 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: lice (via ubst)
MD5: c20379dda5187d8f3236907716fae8ae SHA-1: 0e5499715d7bf34825048a529cc529f4f00b186a SHA-256: d20d8ca1f5e166a0ef59605ebe515ac39717b9b7301b6efac5dd60d707b40d0c
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF was flagged as malicious by ClamAV with the signature Pdf.Exploit.Dropped-94, and a high-confidence ML classifier. Embedded JavaScript streams were detected, indicating the likely execution of exploits within the document. The large size of the embedded JavaScript suggests it is responsible for the malicious payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
37acc1b55518846bb0a3a1df42438f09ffb10d58e16017ebc0ac36f1afda0ab8
pdf-javascript-stream PDF /JS object 76 at offset 0x955 50778 bytes