Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa25e39c2c669008…

MALICIOUS

PDF

59.5 KB Authoring application: sli
MD5: aeb61f86c7f02434be45aeff9f80f092 SHA-1: 3f405d582b219b2839dfe1443fa43dc91d36dff4 SHA-256: fa25e39c2c6690083a163ff20b3ec48d0e9b247e2fef6153491e250eef797d4f
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF was flagged by multiple heuristics, including a high-severity ML classifier and ClamAV detection as 'Pdf.Exploit.Dropped-91'. The presence of JavaScript actions and embedded JS streams indicates an attempt to execute malicious code. While the specific exploit and payload are not detailed, the overall pattern suggests a typical exploit-delivery PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-91 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-91
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.