Malicious PDF — malware analysis report

Static analysis result for SHA-256 e01207551af84b6b…

MALICIOUS

PDF

29.6 KB Created: 2010-02-13 14:06:42 +03:00 Authoring application: [@X\?\!\$] (via ee90b45cf1106fef95ee81de63d7a322)
MD5: 1d101ab1ab28c4e8dd309981ccddc5d0 SHA-1: 74b7f5f11f458731ee985d2cb520bd87951e4b17 SHA-256: e01207551af84b6b7d2ec8b550fec7cd52291d970f0ce676cfb24abe2724d116
82 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript streams and triggers JavaScript actions, indicating an attempt to exploit vulnerabilities within the PDF reader. The ML classifier strongly flags this PDF as malicious. The presence of JavaScript suggests the execution of a secondary payload or malicious script, though the exact nature is obscured by the PDF structure and potential obfuscation. The document body is unreadable, providing no further context on the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9984

Heuristics 5

  • ASCIIHexDecode filter (with exploit indicators) medium PDF_FILTER_HEX
    Hex-encoding filter present alongside exploit delivery indicators — often used to hide payload or shellcode bytes
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85
    ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0018_000.js
1910384b99f45b1ea7c519bd073dd1add0bcdd6dcbfeee703638411c57a97605
pdf-javascript-stream PDF /JS object 18 at offset 0x2414 35714 bytes
javascript_obj0020_001.js
fc12fceac38a2b7dd10c177214fcdf889160c74c19e105aa3a768b274dcb2b18
pdf-javascript-stream PDF /JS object 20 at offset 0x702F 109 bytes