Malicious PDF — malware analysis report

Static analysis result for SHA-256 f9ef1c145f76ee97…

MALICIOUS

PDF

47.1 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: Acrobat PDFMaker 7.0.5 for PowerPoint (via substr)
MD5: 4250cc37dc0ffd0d37d407bf8226c512 SHA-1: 7ddf62748d031aeba0cd306a8744f51a4d231003 SHA-256: f9ef1c145f76ee9732bb2437ca9d71bd46e890ca5dc0f58730ebee803f3a57ca
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The critical ClamAV heuristic indicates this PDF is a known exploit, specifically 'Pdf.Exploit.Dropped-94'. The presence of embedded JavaScript, detected by PDF_JAVASCRIPT and PDF_JS heuristics, strongly suggests the PDF is designed to execute malicious code. This script likely attempts to download and run a second-stage payload, a common technique for exploit documents. The file's metadata and doc body content do not provide further specific clues about the lure, but the exploit detection is definitive.

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
9f065f18ff65b99f361792f8f7ab4328851c3dd70789fe3efc4d851d1c09b358
pdf-javascript-stream PDF /JS object 76 at offset 0x99C 45426 bytes