Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed01e9bdc8b929e3…

MALICIOUS

PDF

17.2 KB
MD5: ec8665a567cf78687c45eb7b7ab31e08 SHA-1: 02c190a4fec261c38153925110cc99d2bd205a5b SHA-256: ed01e9bdc8b929e3bb1d13ebd01c741c9a22486ec01a27b17fd7fa744add981e
154 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious File

This PDF sample was flagged as malicious by a machine learning classifier and ClamAV, indicating a high likelihood of malicious intent. The presence of embedded JavaScript and RichMedia (Flash) content suggests an attempt to exploit vulnerabilities within the PDF reader. The obfuscated filenames within the DOC BODY section further support the malicious nature of the file, likely serving as a lure or payload container.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9981

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload