Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe4d1302203d218b…

MALICIOUS

PDF

61.1 KB First seen: 2022-02-16
MD5: de457b7a5b35e40bb74d462e3d7b7dbf SHA-1: ccaad2db7da94ff9981c8f318cad2c7c2a9132c8 SHA-256: fe4d1302203d218bc68664762e7a481c8e06cbb1d6aca13aa0a6e7b2b0d7f2c6
178 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF contains embedded JavaScript, which is a common technique for delivering malicious payloads. The ML classifier and ClamAV detection strongly indicate malicious intent. The embedded file and JavaScript stream suggest the PDF is designed to download and execute a secondary stage, likely a downloader or dropper, as indicated by the ClamAV signature 'Xls.Downloader.94c25b356b5a6cac-9978798-0'.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9674

Heuristics 7

  • ClamAV: Xls.Downloader.94c25b356b5a6cac-9978798-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.94c25b356b5a6cac-9978798-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0022.bin
55e5c9a04beb12056af49c32f84fbb0de6c9cef1cb624daff1851bb91941121d
pdf-embedded-file PDF EmbeddedFile object 22 at offset 0x1939 50424 bytes
Detection
ClamAV: Xls.Downloader.94c25b356b5a6cac-9978798-0
Obfuscation or payload: likely
Carved artifact entropy is 7.83, consistent with packed or encrypted content.
stream_005_off0000cd14.bin
273270994f8bc3540df1f98f87ea5a0fedd04a2faf7266093c380d47ee63e846
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xCD14 33120 bytes
stream_006_off0000f0e1.bin
9723d90a4d7b32489891627727703e64a23695d030be30af9f7d9579246bbfd3
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xF0E1 929 bytes