Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1b62f7032d666d1…

MALICIOUS

PDF

12.3 KB
MD5: 39632d2486c03dd2b3384022a228e6ea SHA-1: b62101f6315fafcd1431c91d313b07e4c4224344 SHA-256: e1b62f7032d666d1051d63473e0e329b7005a944e9689771299c841402d6fd8b
146 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, identified by multiple heuristics as a stager for executing malicious code. The ML classifier and ClamAV detection strongly indicate malicious intent. The primary technique involves leveraging PDF vulnerabilities to run JavaScript, which is likely used to download and execute a secondary payload, as suggested by the ClamAV detection name 'Pdf.Exploit.Dropped-94'.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • PDF metadata JavaScript eval stager high PDF_METADATA_EVAL_STAGER
    PDF JavaScript reads document metadata fields such as title, subject, or producer, decodes character data with parseInt/String.fromCharCode style helpers, and evals the recovered stage. This is a high-signal exploit-kit staging pattern.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
fc7b70155f32d84f1cc533ab581f6bd6b590b3663b4264756d58f4eb9168f779
pdf-javascript-stream PDF /JS object 76 at offset 0x2F1D 331 bytes