Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e57db9d77fd073a…

MALICIOUS

PDF

187.7 KB
MD5: df36b03c843e742f122623cfed96eadf SHA-1: 36a48a33dc1c012e7ef192df89549a873e4ec738 SHA-256: 1e57db9d77fd073a0560166f6def9905ccb36e5c6bcbecd6458e098daf3d6f11
84 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript

The PDF file exhibits multiple heuristic firings related to JavaScript and XFA forms, with a critical ClamAV detection for obfuscated objects. The presence of embedded JavaScript, despite the document body being unreadable, strongly suggests an attempt to execute malicious code. The primary function appears to be the execution of this obfuscated JavaScript, likely to download and run a second-stage payload.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.3615

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
dee17595e76b7d8c18e2c7d5fe19da1b7fc07174ec72d3b65050172e56eb7eec
pdf-javascript-stream PDF /JS object 12 at offset 0x2E2AF 6262 bytes