MALICIOUS
64
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
T1059.003 Windows Command and Shell
The PDF file is encrypted and contains an OpenAction, which is a common technique to hide malicious content. The presence of JBIG2 encoded streams and the overall structure suggest an attempt to obfuscate a payload. While no specific script was extracted, the heuristics indicate a multi-stage attack where the PDF acts as a dropper for further malicious activity.
Heuristics 4
-
Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JSPDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
-
JBIG2Decode filter medium PDF_JBIG2JBIG2 image decoder present — historically used in zero-click exploits
-
PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LUREPDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
Extracted artifacts 7
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
jbig2_00_off00013c04.bincc349a45708901d3fc4a209d4cbf17e925fc72bceb84fd5ab2ec5085957fc225 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x13C04 | 51568 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
|
|||
jbig2_01_off00024256.bin58b7e050c68922e34bf620daad07f4b5a2ed7d96b621d26c66f0a47092509987 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x24256 | 47584 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
|
|||
jbig2_02_off00032ffc.bin143b236dfa84f69ffc6d8a06aa5077a10406c54b1cd456faea03194248b4ab7d |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x32FFC | 51616 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
|
|||
jbig2_03_off0004351d.bina32ba2b83ef76db6ed99527c60ea6bd17c881cba3ba272bd9c745f057ace07be |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x4351D | 47776 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
|
|||
jbig2_04_off00051d61.bin3eb5b716feda663033c79f349c39c553b8fb96743ee8bc330f0dc521a381e6b0 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x51D61 | 55824 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
|
|||
jbig2_05_off00062763.bin4050a5c248698c9983ecc90015fb4e0e19806ad0b8be9c860813968cb1c96c14 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x62763 | 36576 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
|
|||
jbig2_06_off0006e327.bin89e68ad1e8a946337ec9636240996f92ce1ed4059b9ad36c038efb3be244d3a4 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x6E327 | 53824 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.