Malicious PDF — malware analysis report

Static analysis result for SHA-256 e51f531ce923f5be…

MALICIOUS

PDF

59.2 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: Acrobat PDFMaker 7.0.5 for PowerPoint (via ubst)
MD5: 9968ad3122ecc018be6dcba2c50dffbe SHA-1: dd1cdc4f0a9476c01f9a5e024b468614b7040717 SHA-256: e51f531ce923f5bea2d3973026d0190e1b3006ed7c834835f6a862e3de0e863b
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is identified as malicious by ClamAV (Pdf.Exploit.Dropped-94) and a machine learning classifier. Heuristics indicate the presence of JavaScript actions and embedded JS streams within the PDF structure. The large embedded JavaScript object suggests it is likely responsible for downloading and executing a secondary payload, a common technique for exploit-based PDF malware.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
cc3e6d339d6f496ce71f660817e3c7dc8e4b059d7aa402d5f031f5c8132d9334
pdf-javascript-stream PDF /JS object 76 at offset 0x99B 50607 bytes