Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef5fb9e2bcf46509…

MALICIOUS

PDF

326.2 KB Created: 2015-06-05 03:49:49 Authoring application: Joomla! 1.5 - Open Source Content Management (via TCPDF 2.5.000_PHP4 (http://www.tcpdf.org))
MD5: a88da5d00d9e8df3ae9bd4ce03981efe SHA-1: 13393d68e86bc2dc1dffd03139d28af58c819387 SHA-256: ef5fb9e2bcf46509300231d3b7974577caf0686a6abe0c2d797ab13b2a10e5a2
130 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was detected as malicious by a machine learning classifier and ClamAV, which identified it as Unix.Trojan.PhpBackdoor-9354530-2. A high-severity heuristic firing for PDF_EVAL indicates the presence of executable JavaScript or an embedded interpreter, likely used to exploit a PDF vulnerability. The document body is heavily obfuscated, preventing a clear understanding of its lure, but the ClamAV detection strongly suggests a backdoor payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9895

Heuristics 2

  • ClamAV: Unix.Trojan.PhpBackdoor-9354530-2 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Unix.Trojan.PhpBackdoor-9354530-2
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000c18f.bin
a5337ef1f5a0dfe4dc8fa6b4f3ef847a53624800b5928a0eeef5b888ceecaabc
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xC18F 264072 bytes