Malicious PDF — malware analysis report

Static analysis result for SHA-256 ffd69a4989293d4c…

MALICIOUS

PDF

7.6 KB Created: 2009-10-10 19:42:67 Authoring application: PDF Library 2.6.6 (via PDF Library 10.6.3)
MD5: b5a98c58f3e61c278e3c48f88b76ca66 SHA-1: 2f775ac45ff560c3923636f46835da065dcee982 SHA-256: ffd69a4989293d4c6e36fbef5a264286a250abbe61c6118e251702e464dac261
86 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was flagged as malicious by an ML classifier and exhibits suspicious characteristics including JavaScript actions and embedded JS streams. The presence of ASCIIHexDecode filters further indicates obfuscation techniques commonly used in malicious PDFs. The embedded JavaScript file, 'javascript_obj0007_000.js', is likely responsible for executing the malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ASCIIHexDecode filter (with exploit indicators) medium PDF_FILTER_HEX
    Hex-encoding filter present alongside exploit delivery indicators — often used to hide payload or shellcode bytes
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
6b938a73c906d1bcef9a12c249e600b653951a99e8da52c6338d9bde7495f460
pdf-javascript-stream PDF /JS object 7 at offset 0x268 37089 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long hex-escaped blob(s).