Malicious PDF — malware analysis report

Static analysis result for SHA-256 089218451cf5d5b6…

MALICIOUS

PDF

6.5 KB Created: 2010-08-28 07:57:24 Authoring application: Sejegageiqesoy (via 410b0Golbohoro sazi)
MD5: ca8512439c1a0f780f4bf7e10e08bfce SHA-1: 043b46a04901f44e754273455032c8ab078f7210 SHA-256: 089218451cf5d5b62e9e9e1eccd5dca753d9acca569c50ac7a6b08b38bfbd624
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF contains embedded JavaScript, flagged by multiple heuristics including ML_NYX_PDF_MALICIOUS and ClamAV's Heuristics.PDF.ObfuscatedNameObject. The JavaScript code attempts to execute arbitrary commands, indicated by the use of app.alert and the obfuscated nature of the script, suggesting it's designed to download and execute a secondary payload. The specific JavaScript function `_RM` reconstructs strings, and while the exact payload URL or command is obfuscated, the overall intent is clear.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9986

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0010_000.js
aac1b797b7f4df3946f776d0024554d1424521045e1cc32853762bfc85b57b27
pdf-javascript-stream PDF /JS object 10 at offset 0x118D 1781 bytes