Malicious PDF — malware analysis report

Static analysis result for SHA-256 d50079eb6f7ce193…

MALICIOUS

PDF

8.1 KB
MD5: 99b968607157a0c2826b337ac54053ba SHA-1: 7d1583cf6356dc6d43da701699e8a4dd098b86b9 SHA-256: d50079eb6f7ce193cbdfac4ded7dc152aa7f93f4e9b594247059c785d04d83aa
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF was flagged by multiple heuristics, including a high-severity ML classifier and ClamAV detection for obfuscated objects, indicating malicious intent. The presence of JavaScript actions and embedded JS streams suggests an attempt to execute malicious code, likely to exploit a PDF vulnerability or download a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.