Malicious PDF — malware analysis report

Static analysis result for SHA-256 23a6213ca0cea322…

MALICIOUS

PDF

51.2 KB Authoring application: Paqzehiksagi (via 4a3f8Sodepejavisewake)
MD5: 1f6fed3bdeb031ce4d82504f24328fc1 SHA-1: c8f4a02e86e5e16c28d4f0ccf940af2a3020122b SHA-256: 23a6213ca0cea3223909b8f6907ba6543442dc97b52d8a624736322961460cf7
96 Risk Score

Malware Insights

MITRE ATT&CK
T1559.002 Component Object Model Hijacking

The PDF file contains embedded JavaScript and a RichMedia (Flash) object, both of which are commonly used to deliver malicious content. The ML classifier strongly indicates maliciousness. The embedded JavaScript and Flash file are the primary indicators of the attack vector, likely leading to further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
380c1c903c43f1ea2075f889f94d4808.swf
31d7be534d8b8f64e7dc9a7fc87b614bbaa76f3416ed20c304a0da33a06ca63d
pdf-embedded-file PDF EmbeddedFile object 15 at offset 0x1034 43900 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
javascript_obj0020_000.js
a93bb995f242b8a2d4b3152ea6d152ab0764fe2e1ac85b11e8208f526974f40b
pdf-javascript-stream PDF /JS object 20 at offset 0xBDE2 3926 bytes