Malicious PDF — malware analysis report

Static analysis result for SHA-256 0dbefd10297d1df2…

MALICIOUS

PDF

92.7 KB Created: 2003-02-02 15:16:04 -06:00 Authoring application: OmniForm Premium (via OmniForm Converter for PDF)
MD5: 6a8c51abc15c0277c0182000da5d448f SHA-1: 13bc5766a43730da6e298d9965f2241588b64bbc SHA-256: 0dbefd10297d1df2c4abd5db5a61098384e1191aabd0bc9a360a77ca336aa61c
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The sample is a PDF file that contains embedded JavaScript and an AcroForm button with an action trigger. The ML classifier strongly indicates maliciousness. The presence of JavaScript and exploit indicators suggests the document is designed to execute malicious code upon opening, likely to download a second-stage payload. The benign URLs extracted do not provide further indicators.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9784

Heuristics 5

  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85
    ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/iX/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/