Malicious PDF — malware analysis report

Static analysis result for SHA-256 f87cfe301fb2a21a…

MALICIOUS

PDF

69.5 KB
MD5: ad5aaa4939f8fc0cbf71b28d955f7d68 SHA-1: 8a08ab51f1c1c53c102bab3a0c7813bbdb186433 SHA-256: f87cfe301fb2a21aa09ea9a964a5c79ec82ef4cc31198fa333ed142b0c6b76ee
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1055.012 Process Injection: Process Hollowing

The PDF file contains a Base64-encoded PE payload, identified by the PDF_BASE64_PE_PAYLOAD heuristic. The payload utilizes process injection APIs such as VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread, indicating an attempt to execute malicious code within a legitimate process. The SHA256 hash of the embedded executable is also provided as an IOC.

Heuristics 1

  • Base64-encoded Windows executable payload in PDF critical PDF_BASE64_PE_PAYLOAD
    PDF text contains a long base64 blob that decodes to a verified Windows PE executable. This catches payloads hidden after EOF, inside comments, or in plain text outside normal PDF streams.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
base64_pdf_pe_000002fe.exe
cac25a0c85ff0522a7105b86ac53326b6c5a8b9031d9ab76d5f39249c561bd20
embedded-pe PDF raw base64 PE payload at offset 0x2FE 52736 bytes