Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5b1e08e6882b077…

MALICIOUS

PDF

47.2 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: Acrobat PDFMaker 7.0.5 for PowerPoint (via substr)
MD5: 6dc3c816b661e1f7fe3321217f779eac SHA-1: 38a30c81a73b62a7b2e3ff6b8dfcfd0281a22dc7 SHA-256: e5b1e08e6882b0775ea55ccbcd49cc9de524a21bdc0d19b54a01591e3aa0405a
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The ClamAV detection 'Pdf.Exploit.Dropped-94' strongly suggests this JavaScript is malicious and likely exploits a vulnerability within the PDF reader to execute. The large size of the embedded JavaScript stream (45564 bytes) further supports the idea that it contains significant malicious code, possibly for downloading and executing a secondary payload. The document body text appears to be metadata and copyright information, offering no direct clues to the attack's pretext.

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
28136b7b9d63b8b7ec601322826edb01fe7555834d979a4e0e0551b98579da10
pdf-javascript-stream PDF /JS object 76 at offset 0x99C 45564 bytes