Malicious PDF — malware analysis report

Static analysis result for SHA-256 d560f0834765ac1f…

MALICIOUS

PDF

25.8 KB Created: 2006-02-01 14:14:12 Authoring application: Wegoptyr (via HghTc6Fs)
MD5: df168d93673575d5cfd957a635490c36 SHA-1: 985ac10d55a27e24991d1630f06316c388b55ced SHA-256: d560f0834765ac1ff10d38541b984d4b1d1f23661c2ee481a796d06ccf9a1245
88 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 Command and Scripting Interpreter: PowerShell

This PDF file contains embedded JavaScript streams, flagged by heuristics as suspicious. The JavaScript utilizes eval() calls, indicating code execution. The ML classifier strongly suggests malicious intent. The primary attack pattern involves leveraging these JavaScript components to likely download and execute further malicious content, although the exact payload and delivery mechanism are not fully discernible from the provided static analysis.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
2bc4825c7b861a78835609c8ffd51dcdfd254d6896baaae215c9a1a67cd81407
pdf-javascript-stream PDF /JS object 7 at offset 0x1EE 25333 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s).
javascript_obj0007_001.js
79f8aa358cd3e8ead5ca748c24c024e447d6c5f2985247c58618daf07d09fb9e
pdf-javascript-stream PDF /JS object 7 at offset 0x1EE 25058 bytes