Malicious PDF — malware analysis report

Static analysis result for SHA-256 22b90d6cddf1867e…

MALICIOUS

PDF

52.2 KB Authoring application: 376377000P000D000F000C000r000e000a000t000o000r000 000V000e000r000s000i000o000n000 0000000.0009000.0009 (via GPL Ghostscript 8.70)
MD5: 5c7653c59e16212dbfe69bbd96cef23c SHA-1: 9093ca6333890a89a0df9858806705270e966454 SHA-256: 22b90d6cddf1867e75ea60861cd61b954d534fee0e017d134041e43e52dcef81
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by ClamAV with 'Heuristics.PDF.ObfuscatedNameObject', indicating obfuscated content. Additionally, heuristics detected embedded JavaScript, suggesting an attempt to execute malicious code. The presence of JavaScript actions and streams points towards a downloader or exploit delivery mechanism. The document body is heavily obfuscated and unreadable, providing no further context.

Heuristics 4

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/iX/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0006_000.js
5a69aa3d1ce6b08ab8f6ac7d5f3d2723319285c3fa649be9864637d4d76926c4
pdf-javascript-stream PDF /JS object 6 at offset 0x1A9 6274 bytes
font_00_sfnt_off00004ab4.bin
6a55835f4942c92d806fca6e47800d2f5ac8b613cd5ccb9e2e61d5896fec304b
pdf-font-stream PDF embedded font (sfnt) at offset 0x4AB4 48604 bytes