Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee367ff6389e2795…

MALICIOUS

PDF

2.0 KB
MD5: 57a57e2d08f1fa725594ecbd44e6cf80 SHA-1: 3e08234ac5f8199dfd0ec3729b599cf5709d1ecf SHA-256: ee367ff6389e279523c3d60c18f3ba1b79ab99f9261be4e8497344485c20c25c
104 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The PDF document contains the EICAR test string and metadata indicating it's designed to prompt the user to save and launch the EICAR test file. Embedded JavaScript streams and PDF-specific filters are used to achieve this, aligning with a malicious intent to trigger anti-virus detection. The critical ClamAV detection of 'Eicar-Test-Signature' confirms the nature of the payload.

Heuristics 5

  • ClamAV: Eicar-Test-Signature critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Eicar-Test-Signature
  • ASCIIHexDecode filter (with exploit indicators) medium PDF_FILTER_HEX
    Hex-encoding filter present alongside exploit delivery indicators — often used to hide payload or shellcode bytes
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
c79586b6ce33258a4a3246f592054a0720afaa39e08ec5d2fa6c2c1d19c42b91
pdf-javascript-stream PDF /JS object 8 at offset 0x4CA 58 bytes
javascript_obj0008_001.js
a99f0aad140b19a3f2f03812ca412c6d983fae48b9344738a95bf360fb8f644c
pdf-javascript-stream PDF /JS object 8 at offset 0x4CA 56 bytes