Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9b360839dbbeb80…

MALICIOUS

PDF

409.3 KB Created: 2011-01-21 14:48:38 -08:00 Authoring application: Adobe Acrobat 9.0 (via Adobe Acrobat 9.0 Image Conversion Plug-in)
MD5: 151ee41c923b42a4e10193deb98e66a0 SHA-1: 4528db9daecc04d26e4f9016a3d7441938397ab5 SHA-256: e9b360839dbbeb800658494dc9ed378c25a240c09874f760577f2351100f92de
70 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

This PDF file was flagged as malicious by an ML classifier and contains embedded JavaScript. The JavaScript action and embedded JS stream heuristics indicate that the script is likely responsible for downloading and executing a second-stage payload. The presence of JBIG2Decode filters and image-only lures suggests an attempt to obscure malicious content. No specific family could be identified.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8909

Heuristics 6

  • JBIG2Decode filter medium PDF_JBIG2
    JBIG2 image decoder present — historically used in zero-click exploits
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/tiff/1.0/

Extracted artifacts 13

Files carved from inside the sample during analysis.

FilenameKindSourceSize
jbig2_00_off000015b9.bin
eb99ee6a02b8f8ec088c80a0e3ebd5ac6024fe07454c79f75c016ab10a8859c7
pdf-jbig2-stream PDF JBIG2 stream at offset 0x15B9 24598 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_01_off00007c0e.bin
3da224089aea2a4bc73c8d3969019942b2e9b3aa57bacece5744aa2166391a34
pdf-jbig2-stream PDF JBIG2 stream at offset 0x7C0E 27580 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_02_off0000ee09.bin
0882170e1f135da63163e2e5160faa8175fda9bd7f7a02370a86655f148b453a
pdf-jbig2-stream PDF JBIG2 stream at offset 0xEE09 35377 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_03_off00017e79.bin
afd3cc7d62e9fa6c506b439a2c0bde4598dd448fc720585931a65354a4b256d2
pdf-jbig2-stream PDF JBIG2 stream at offset 0x17E79 31115 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_04_off0001fe3d.bin
c8d94b054ec21da4a11a03a051c5a20e991dfa424d1123529d4184b8aa785188
pdf-jbig2-stream PDF JBIG2 stream at offset 0x1FE3D 31220 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_05_off00027e70.bin
b3a6add6fc5f4b5952a29a716f08a4b67f5caad88da27926acd38caaa0f0a7e6
pdf-jbig2-stream PDF JBIG2 stream at offset 0x27E70 26178 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_06_off0002eae9.bin
0099af16da09a4706afe4cd136f52c1bdd62a1d059352819ba2833a071b791af
pdf-jbig2-stream PDF JBIG2 stream at offset 0x2EAE9 33497 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_07_off00037401.bin
28964259ba16bff55df9c39339f65d7b3a6e82179f06a7246759bfca20219743
pdf-jbig2-stream PDF JBIG2 stream at offset 0x37401 21233 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_08_off0003d013.bin
64245d894adf61e45d60b2a65f2d59eb5b45700b4611d4ad3c38644fde546607
pdf-jbig2-stream PDF JBIG2 stream at offset 0x3D013 34321 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_09_off00045c5b.bin
983038922380772d442f1f7162aa6bda3dedfed0b1044fbf34fe6b856a355788
pdf-jbig2-stream PDF JBIG2 stream at offset 0x45C5B 31571 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_10_off0004dde5.bin
08361214adb97fed5209b30cde8ea4d55a87355207479d24d7e45c5dc317a6e8
pdf-jbig2-stream PDF JBIG2 stream at offset 0x4DDE5 23495 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_11_off00053feb.bin
80c9cadbd5efa1e014beadc40437f3b68daac8c3bedde9b377953b1fdec4b0d1
pdf-jbig2-stream PDF JBIG2 stream at offset 0x53FEB 30772 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_12_off0005be5d.bin
c25513042db47abdca553b2d3ef9f77be97280757240684fbc68a0aa94afd53e
pdf-jbig2-stream PDF JBIG2 stream at offset 0x5BE5D 36024 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.