Malicious PDF — malware analysis report

Static analysis result for SHA-256 1f7a2f4a2ba1e568…

MALICIOUS

PDF

81.2 KB Created: 2009-07-17 18:58:01 Authoring application: Scribus 1.3.3.13 (via Scribus PDF Library 1.3.3.13)
MD5: 1e050d3568bd80b994f742ab5d0b72b6 SHA-1: 890e8c549f23d17a1bbca3142681183ade6f5114 SHA-256: 1f7a2f4a2ba1e5682625fbf164596c67d9183f06aa8dfd8ead66901e031cea77
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

This PDF file was flagged as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. Embedded JavaScript streams were detected, suggesting the file is designed to execute code upon opening. The primary attack pattern involves leveraging these JavaScript streams, likely to download and execute a second-stage payload. While specific IOCs like URLs or hashes are not directly present in the extracted evidence, the presence and nature of the embedded JavaScript streams are strong indicators of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 1 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xap/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/exif/1.0/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0015_000.js
7fb1413a28a6d28018ccc39093a5417d25cc106f84b52f6c6e6be37e93e5e29a
pdf-javascript-stream PDF /JS object 15 at offset 0x115FE 44536 bytes
javascript_obj0016_001.js
77de05195a9ce1073d524e2424214ed22eb9fa915b0963bef0186136e718be42
pdf-javascript-stream PDF /JS object 16 at offset 0x13EE9 266 bytes
javascript_obj0017_002.js
9d77c95550bba0e841a421b6081df31dc9692da05578086aaee3267a2d7bab15
pdf-javascript-stream PDF /JS object 17 at offset 0x14010 232 bytes