Malicious PDF — malware analysis report

Static analysis result for SHA-256 dea68ddf5705d446…

MALICIOUS

PDF

26.9 KB Created: 2006-02-01 14:14:12 Authoring application: Wegoptyr (via HghTc6Fs)
MD5: c0dbd643397767d0d55bd58bc8f31a3a SHA-1: de8fde72c154cc57976ac0d7a10cb7adb9574101 SHA-256: dea68ddf5705d446e61f4876721e4b7172b88183a5c56f6d24bc0c850bf464d7
150 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings including PDF_JAVASCRIPT and PDF_JS. A high-confidence finding of PDF_EVAL points to the use of the eval() function, a common technique for executing obfuscated code. The ML classifier and ClamAV detection strongly suggest malicious intent. The obfuscated JavaScript likely downloads and executes a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 6

  • ClamAV: Pdf.Exploit.Agent-22685 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-22685
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PSSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
624ab6dec096586a4f82e38d3a3ecd9ccafb31f85cb6821c8e700b18c8579992
pdf-javascript-stream PDF /JS object 7 at offset 0x1EE 26160 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).
javascript_obj0007_001.js
a643be3922b04e091143970e815a668136ac2a80fca1d230798a4c1ee3202e95
pdf-javascript-stream PDF /JS object 7 at offset 0x1EE 534 bytes