Malicious PDF — malware analysis report

Static analysis result for SHA-256 05f415740dfef338…

MALICIOUS

PDF

6.3 KB Authoring application: Woibneqeni (via 1b513Uzenwzijecijawida)
MD5: be76591bf70ec4303cc11b1f16791543 SHA-1: 9b1c26cc606b215fe23c4f6e801318e5f9c317b5 SHA-256: 05f415740dfef338413179dec4c6172737b933523223aa7d7c8044eb8751ddab
86 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

This PDF file contains obfuscated JavaScript that is designed to be executed. The script reconstructs and evaluates further JavaScript code, which is then used to extract and potentially execute a second-stage payload. The presence of PDF-specific stager heuristics and the ML classifier strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Page-word XOR JavaScript eval stager high PDF_PAGE_WORD_XOR_EVAL_STAGER
    PDF JavaScript enumerates rendered page words with getPageNthWord/getPageNumWords, extracts encoded byte fragments, XOR-decodes the stage with char-code helpers, and evals the result. This is an old exploit-kit staging pattern and is not normal document JavaScript.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0010_000.js
e5fb7241b86520d30618ed164f0373984e043b354e933bd4bfa81c848e06fafc
pdf-javascript-stream PDF /JS object 10 at offset 0x11B0 1464 bytes