Malicious PDF — malware analysis report

Static analysis result for SHA-256 e73ca59e342bf00b…

MALICIOUS

PDF

27.4 KB
MD5: f07acd88819dab5dd0e04332e0b36bfa SHA-1: 15b93839ae97caef6bea102d761941c1bb057dea SHA-256: e73ca59e342bf00babf2a30c3b8c43773e5e7e5d82da5aee7841d5fe77d874a4
148 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.001 Malicious Link T1071.001 Web Protocols T1204.002 Malicious File

The PDF sample contains heavily obfuscated JavaScript, including multiple eval() and unescape() calls, indicative of exploit kit activity. The critical CVE-2008-2992 heuristic firing confirms the use of a known exploit targeting Adobe Reader. The embedded JavaScript streams and deobfuscated stages suggest the primary function is to download and execute a secondary payload, likely from a remote server. The ML classifier strongly supports a malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • util.printf — CVE-2008-2992 critical CVE exact CVE_2008_2992
    PDF JavaScript calls util.printf() — CVE-2008-2992 is a stack buffer overflow in Adobe Reader triggered by a long format-specifier argument. Widely exploited in the wild after disclosure. (identified after JavaScript deobfuscation)
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj111711_000.js
c8decf1ec05f5fdb023d067fb3e2aa6619e9a624c9ee04755d2312f2c28bc188
pdf-javascript-stream PDF /JS object 111711 at offset 0x18E 3982 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 5 long base64-like blob(s).
javascript_obj111712_001.js
e5252360b0d6f9c5ef000f69f72e78e7e5b52453389aca43b29ba5a1f624d380
pdf-javascript-stream PDF /JS object 111712 at offset 0x1152 19056 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 4 long base64-like blob(s).
javascript_obj111713_002.js
9fd6a3fd5a1ca17c8141c80595e5a015c93264ddd6398424bdc6b636240de5d3
pdf-javascript-stream PDF /JS object 111713 at offset 0x5BF8 4399 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 4 long base64-like blob(s).
legacy_pdfkit_stage_000.js
a63d87f2b143513c65d1743d1dc1458eace0797e16ff17319fa0a362817b3dff
deobfuscated-js multi-marker percent-array decoded JavaScript at offset 0x1152 1413 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s).
legacy_pdfkit_stage_001.js
e282e90aa5eca950df2ca38b720cea9e6025f175e744e4f996f2c8820ba8b08c
deobfuscated-js multi-marker percent-array decoded JavaScript at offset 0x5BF8 385 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
legacy_pdfkit_stage_002.js
c6ed0250e9ba7991446187d3f21f95da030a85919c190dc1fa364a194b510be3
deobfuscated-js multi-marker percent-array combined decoded JavaScript at offset 0x1152 1799 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).