Malicious PDF — malware analysis report

Static analysis result for SHA-256 1c275abf6227cd26…

MALICIOUS

PDF

7.3 KB Created: 2010-09-16 18:52:20 Authoring application: Qabifagevafa (via cbc54Tiqotezozav)
MD5: 66066853a1c04044001e32d4cce4c3d2 SHA-1: 966f02f3f3605179e72a623250dc4060496ea981 SHA-256: 1c275abf6227cd26ba63026017c813384fb2ed284fc3bd18d975f3ebe35eae57
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1027 Obfuscated Files or Information

The file is a PDF document flagged by ClamAV with 'Heuristics.PDF.ObfuscatedNameObject', indicating obfuscated content. Embedded JavaScript was detected, suggesting an attempt to execute code. The obfuscated nature of the JavaScript and the PDF structure points towards an attack pattern involving malicious script execution, likely for payload delivery or exploitation. The exact intent of the script is unclear due to obfuscation, but the critical ClamAV detection and the presence of JavaScript are strong indicators of malicious activity.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
ff85b44f7d06834e69a161aee8e28b7340c56fef50ee1649100cb6f376ea5386
pdf-javascript-stream PDF /JS object 11 at offset 0x1364 2324 bytes