Malicious PDF — malware analysis report

Static analysis result for SHA-256 e45138471e34a6bf…

MALICIOUS

PDF

47.2 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: Acrobat PDFMaker 7.0.5 for PowerPoint (via substr)
MD5: 9e10660c39f28db131cd67c4c7a22aeb SHA-1: 5217558bd0a17bccd2e26ee94870f283503b2e8e SHA-256: e45138471e34a6bf713030791a85e4ed85b9a9a2af51f3aa10f39f6a37be4c6d
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The file is identified as a malicious PDF by ClamAV and a machine learning classifier. Heuristics indicate the presence of JavaScript actions and embedded JS streams, suggesting an attempt to execute malicious code. The ML classifier's high confidence score further supports the malicious nature of the document. The embedded JavaScript is likely responsible for downloading and executing a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
2813cff10a11ede4767374b59fad5cfa0e808ca242602eff434c0366f8cae0d7
pdf-javascript-stream PDF /JS object 76 at offset 0x99C 45562 bytes