Malicious PDF — malware analysis report

Static analysis result for SHA-256 eaf5af9e744bd7f1…

MALICIOUS

PDF

47.3 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: Acrobat PDFMaker 7.0.5 for PowerPoint (via substr)
MD5: 9c0090c29f032ed02b02b1640537d6f2 SHA-1: bc1e5a55093cb74f5d295150068c62cac155ef82 SHA-256: eaf5af9e744bd7f167551cbd5f379a8c6485aeed5b2f2ea890738dfa75e0d100
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was flagged as malicious by ClamAV with the signature 'Pdf.Exploit.Dropped-94' and a high-confidence ML classifier. Heuristics indicate the presence of embedded JavaScript, which is a common technique for exploiting PDF vulnerabilities. The JavaScript action at offset 0x27A and the embedded JS stream at offset 0x2ED strongly suggest that the script is designed to download and execute a secondary payload, aligning with the 'Dropped' classification.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
bc1828cb4fa6a4fbfdbb084736bc928004a51b520f2b15bdf55fd5abc9224c75
pdf-javascript-stream PDF /JS object 76 at offset 0x99C 45688 bytes