Malicious PDF — malware analysis report

Static analysis result for SHA-256 e3cfa93b866eecd9…

MALICIOUS

PDF

7.3 KB Created: 2009-07-13 19:22:54 Authoring application: vZVi (via JJ9v)
MD5: f96ef633dd5059c86249500dc6e2c2d3 SHA-1: 0f47b462841e7f7dc58edfdcb96f651ea6fca9fd SHA-256: e3cfa93b866eecd9bb5f695ad97fa1d0447275e0e447e66da8e9bec714315ae0
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript T1204.002 Malicious JavaScript

The PDF sample was flagged as malicious by multiple high-confidence heuristics, including ML classification and correlated JavaScript signals. The embedded JavaScript, although obfuscated, is indicative of a malicious action. The authoring application 'vZVi (via JJ9v)' is noted as a potential indicator.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Correlated malicious PDF JavaScript signals critical PDF_CORRELATED_MALICIOUS_JS
    PDF JavaScript or auto-action content is corroborated by exploit staging, ML, or suspicious extracted-artifact findings. This correlation promotes old exploit-kit PDFs that otherwise remain in the suspicious band because each individual signal is intentionally weighted conservatively.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.