Malicious PDF — malware analysis report

Static analysis result for SHA-256 2483865362d5437f…

MALICIOUS

PDF

501.9 KB Created: ìÄhInòzQà}»&ö\‡Š«kÙç0r¦Já?½.ðÓ#X|âr¯<ýÐ |ôf¬ Authoring application: (¢S’2·& Ñ{Í=4Ãë¶@x­ȞÅAo[}>± SP?^ ;Çb |̎]ÄØ„Ë¡/<Y¤t ÁRÙÈ1a*=
MD5: 60522cbd8764d29b3c3a139a95669432 SHA-1: 62ebe2c9e4bc3188a2f2181608f1c6d1f7564750 SHA-256: 2483865362d5437f3b98af104d3e2d4d557809fcf077a0e5f9d4666a92bab684
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1059.003 Windows Command and Shell

The PDF file is encrypted and contains an OpenAction, which is a common technique to hide malicious content. The presence of JBIG2 encoded streams and the overall structure suggest an attempt to obfuscate a payload. While no specific script was extracted, the heuristics indicate a multi-stage attack where the PDF acts as a dropper for further malicious activity.

Heuristics 4

  • Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JBIG2Decode filter medium PDF_JBIG2
    JBIG2 image decoder present — historically used in zero-click exploits
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
jbig2_00_off00013c04.bin
cc349a45708901d3fc4a209d4cbf17e925fc72bceb84fd5ab2ec5085957fc225
pdf-jbig2-stream PDF JBIG2 stream at offset 0x13C04 51568 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
jbig2_01_off00024256.bin
58b7e050c68922e34bf620daad07f4b5a2ed7d96b621d26c66f0a47092509987
pdf-jbig2-stream PDF JBIG2 stream at offset 0x24256 47584 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
jbig2_02_off00032ffc.bin
143b236dfa84f69ffc6d8a06aa5077a10406c54b1cd456faea03194248b4ab7d
pdf-jbig2-stream PDF JBIG2 stream at offset 0x32FFC 51616 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
jbig2_03_off0004351d.bin
a32ba2b83ef76db6ed99527c60ea6bd17c881cba3ba272bd9c745f057ace07be
pdf-jbig2-stream PDF JBIG2 stream at offset 0x4351D 47776 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
jbig2_04_off00051d61.bin
3eb5b716feda663033c79f349c39c553b8fb96743ee8bc330f0dc521a381e6b0
pdf-jbig2-stream PDF JBIG2 stream at offset 0x51D61 55824 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
jbig2_05_off00062763.bin
4050a5c248698c9983ecc90015fb4e0e19806ad0b8be9c860813968cb1c96c14
pdf-jbig2-stream PDF JBIG2 stream at offset 0x62763 36576 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
jbig2_06_off0006e327.bin
89e68ad1e8a946337ec9636240996f92ce1ed4059b9ad36c038efb3be244d3a4
pdf-jbig2-stream PDF JBIG2 stream at offset 0x6E327 53824 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.