Malicious PDF — malware analysis report

Static analysis result for SHA-256 18fb4f6ee9c17244…

MALICIOUS

PDF

7.1 KB Authoring application: Wezolokofecpo (via e7c70Nworeticakebi)
MD5: afb4e5d593cd873fdc8ad55655edf3bc SHA-1: f3b21abf12fdf29281e65dfe54f666b4786446ed SHA-256: 18fb4f6ee9c17244022226da45ab7b03829bda34d8309633d51529b15097315f
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

This PDF file contains obfuscated JavaScript, flagged by multiple heuristics and a machine learning classifier as malicious. The embedded JavaScript is designed to execute arbitrary code, strongly suggesting it acts as a downloader for a second-stage payload. The authoring application metadata also indicates a suspicious origin.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9953

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
437a5d40b54247c17dfb3ac60e39d3ecfad672a269694af1851a077d9726a8d2
pdf-javascript-stream PDF /JS object 11 at offset 0x1342 2272 bytes