Malicious PDF — malware analysis report

Static analysis result for SHA-256 d337e2be988227ea…

MALICIOUS

PDF

4.1 KB Created: 2008-07-26 19:43:58 Authoring application: Scribus 1.3.3.12 (via Scribus PDF Library 1.3.3.12)
MD5: 6dc4ac10cccfc17e8457cc25c3567216 SHA-1: d6641cca6b64acae3a7cfa83780ef035038b9c7c SHA-256: d337e2be988227ea54e46876d237dc420b8a49351f2e729b2edf3588c4634e96
98 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1059.007 JavaScript

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings including PDF_JAVASCRIPT, PDF_JS, PDF_EVAL, and PDF_UNESCAPE. The JavaScript stream is obfuscated and utilizes eval() and unescape() functions, suggesting an attempt to hide malicious code execution. The primary intent appears to be the execution of this obfuscated JavaScript, likely to download and execute a second-stage payload or perform other malicious actions.

Heuristics 5

  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0014_000.js
bc26972dbf28845ff2a0b15e64912d3350102bbef7b407b50936707c4390c747
pdf-javascript-stream PDF /JS object 14 at offset 0x368 33886 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).