Malicious PDF — malware analysis report

Static analysis result for SHA-256 1d6f84c6da029adb…

MALICIOUS

PDF

1.30 MB Created: ʍ»ïvËð(¬d*Y‚1Â_-ÔGtg” Authoring application: ÞÓïœ)Z‹º~î%t•7ßC3ÔQ (via ÍáÀŒxµèOø5sÚhžt…)
MD5: 64c5c0761fd7db6c9b8f84652818bbed SHA-1: 8783fe713a933db619212a044dca82aedca2aebc SHA-256: 1d6f84c6da029adb9e63e95fdd4e4851ad0e0ad166de88bdd55a84990e7990bf
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.003 Phishing: Spearphishing Attachment T1059.003 Command and Scripting Interpreter: Windows Command Shell

The PDF file is identified as malicious due to the presence of an encrypted structure and an embedded JavaScript action, which is a common technique to conceal malicious content from static analysis. The JBIG2Decode filter and numerous extracted JBIG2 streams suggest complex image encoding, potentially used to hide exploit code or malicious content within the document. The lack of readable document body text and the obfuscation methods point towards a downloader or exploit delivery mechanism.

Heuristics 4

  • Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JBIG2Decode filter medium PDF_JBIG2
    JBIG2 image decoder present — historically used in zero-click exploits
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 32

Files carved from inside the sample during analysis.

FilenameKindSourceSize
jbig2_00_off000071ee.bin
f8285bd1915063901d09a37561abf8ea25e1b5d52b3d26a4bcbf88af3d35eb97
pdf-jbig2-stream PDF JBIG2 stream at offset 0x71EE 7374 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_01_off000090f2.bin
b868adaaa2dd09c19e6f9273b31650f29d767cfc97c6e377b7e5e434129be07f
pdf-jbig2-stream PDF JBIG2 stream at offset 0x90F2 10631 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_02_off0000bcae.bin
111e469a75b9c679136217ab8c4f4b9ae9f9607290848f3828fcaadc29b5623d
pdf-jbig2-stream PDF JBIG2 stream at offset 0xBCAE 4439 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_03_off0000d041.bin
39c86a0068022e39dc7d0598221229cc47222e0c1442977af0ac2c7ff3a486af
pdf-jbig2-stream PDF JBIG2 stream at offset 0xD041 9057 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_04_off0000f5de.bin
f56ffe3026e8911aaa4f8e5166c16770511079f259dcb54441e6c2d9624d331c
pdf-jbig2-stream PDF JBIG2 stream at offset 0xF5DE 5608 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_05_off00010e01.bin
2e73403f24def1f0a2f4ae43a6253bcd374a7ffa92039dfec723cbf492f237d7
pdf-jbig2-stream PDF JBIG2 stream at offset 0x10E01 6889 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_06_off00012b23.bin
8c9f34155a2f99cb94f2fe7a526aef96dabe21d60373d558d115be84345561f7
pdf-jbig2-stream PDF JBIG2 stream at offset 0x12B23 3701 bytes
jbig2_07_off00013bd1.bin
0f9b5e540d5914251b450bde5091decf91a7d64c3e987921ce74d4f3dbf6cdfe
pdf-jbig2-stream PDF JBIG2 stream at offset 0x13BD1 7850 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_08_off00015cb6.bin
c7eed2253c24d21c937f128c6e0637a3c459d3d22502c5a8cd63bf2879fc5fe7
pdf-jbig2-stream PDF JBIG2 stream at offset 0x15CB6 8712 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_09_off000180f9.bin
1a57f3642084b7e93e6e33bbfee16405bcfcfffec59146ac0d09d18a025f3385
pdf-jbig2-stream PDF JBIG2 stream at offset 0x180F9 8528 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_10_off0001a487.bin
6f77a5d190f1ae5a33f0e4b1b4a8995629268e1f5bc5e6160ec9b71dd7939c0a
pdf-jbig2-stream PDF JBIG2 stream at offset 0x1A487 6910 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_11_off0001c1c3.bin
1f711d1ab8033f1fb4285d4b98d288ea64632682bda146c5a97e7d1b56a8c354
pdf-jbig2-stream PDF JBIG2 stream at offset 0x1C1C3 7350 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_12_off0001e0b7.bin
a54f4165a8907fd1047cefc6c024873753642d61b57ab30cd03774d46cfc9692
pdf-jbig2-stream PDF JBIG2 stream at offset 0x1E0B7 8693 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_13_off000204ea.bin
d51102ba24710cbc639ec326cb7fc79b5f81b8e0ef886a58a0cd1a14316f0d5f
pdf-jbig2-stream PDF JBIG2 stream at offset 0x204EA 8411 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_14_off00022803.bin
ef6dd0dc72677f6f46b210fadd83fafe587875570d303fc01d6ce7ba6565d79c
pdf-jbig2-stream PDF JBIG2 stream at offset 0x22803 8471 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_15_off00024b55.bin
bb8bffec8dcea45055ff2f7e4f3fd597b7c2078073f304e7e908456d372c92f1
pdf-jbig2-stream PDF JBIG2 stream at offset 0x24B55 7991 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_16_off00026cc9.bin
e46e42575060df43111f6d8f4454d748301996731b0cd672b4de8d9ff100f756
pdf-jbig2-stream PDF JBIG2 stream at offset 0x26CC9 8390 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_17_off00028fca.bin
afa1de618c8ac97473d11d77aee1ee290be3db1176a03ffb750742c07e887b29
pdf-jbig2-stream PDF JBIG2 stream at offset 0x28FCA 8260 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_18_off0002b24c.bin
615ddb01c03dc61a17ef404a6916c62c907ab1ea5eef888000ce6ee4b65b134f
pdf-jbig2-stream PDF JBIG2 stream at offset 0x2B24C 7282 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_19_off0002d0f8.bin
d61955eebbf438250068f17dc1252f549117b070154dbec998938587bcfc3ad9
pdf-jbig2-stream PDF JBIG2 stream at offset 0x2D0F8 6155 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_20_off0002eb41.bin
42891488316e6eb60117051666fe17784ee5c54cd9028f88290f95757d8a1252
pdf-jbig2-stream PDF JBIG2 stream at offset 0x2EB41 5653 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_21_off0003039c.bin
6b7619195c140d141ad24257be6f169664a933101add437e40bdb1ff8c4a6521
pdf-jbig2-stream PDF JBIG2 stream at offset 0x3039C 4859 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_22_off000318dd.bin
0186472c51c4700d6c31f9fb7338b9caff017c61a115d4aa961aa109b0051065
pdf-jbig2-stream PDF JBIG2 stream at offset 0x318DD 5199 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_23_off00032f72.bin
8eb696ebb64931622aa727a4563a36e115be69c3aa61654d8c081462477c7547
pdf-jbig2-stream PDF JBIG2 stream at offset 0x32F72 6306 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_24_off00034a5b.bin
1d6f011ede74446c8dbfc4facbb12fe72fbeb28a34db102e83a83b9d4eb59002
pdf-jbig2-stream PDF JBIG2 stream at offset 0x34A5B 6624 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_25_off00036681.bin
e1ec6767793f450c7ed6d1f95e974904c51cd785f71ad8ab262da002ec290a8d
pdf-jbig2-stream PDF JBIG2 stream at offset 0x36681 5856 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_26_off00037fa3.bin
ebd77ab3ba86126a345622a50b5d2362b2d036d0d8d80dc35abe73ab019734eb
pdf-jbig2-stream PDF JBIG2 stream at offset 0x37FA3 2225 bytes
jbig2_27_off00038a98.bin
aa3ee1b1bc5f210ac5d9c124d921b39a8876a03c34695013b0735428b76c1ee4
pdf-jbig2-stream PDF JBIG2 stream at offset 0x38A98 8585 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_28_off0003ae64.bin
6103ef8b21d4ac576c7ddb2798d742cc966638e56aefb6747f49ede350bbfba9
pdf-jbig2-stream PDF JBIG2 stream at offset 0x3AE64 4585 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_29_off0003c293.bin
a8fa4b55aab2ded26e5a0ca295c9415139754a6ed67d9df8593a5e8ceb77697a
pdf-jbig2-stream PDF JBIG2 stream at offset 0x3C293 4554 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_30_off0003d69f.bin
9a36f517d613ea1da03363186a70841ab7283342dc68df9a5eed0a45f1bf2dbd
pdf-jbig2-stream PDF JBIG2 stream at offset 0x3D69F 4333 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
jbig2_31_off0003e9d2.bin
83dc2f8df8c17c33f2b9e413c0ed14fb9f9ced4a4b79da21b57d4ff4fed70e5e
pdf-jbig2-stream PDF JBIG2 stream at offset 0x3E9D2 5573 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.