Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a3d92bf0e9d3be1…

MALICIOUS

PDF

45.5 KB
MD5: aa9a073a68a5c6848c2b6457f4a8f570 SHA-1: bf0ac54f207cc001767a5d017c56f57fca9e57a9 SHA-256: 2a3d92bf0e9d3be1552fc4b885845e716d6a1b22886f8fd485dff5176d459691
114 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was flagged as malicious by a machine learning classifier and ClamAV, with specific detections for obfuscated objects and JavaScript actions. The presence of embedded JavaScript streams indicates an attempt to execute code. While the document body is heavily obfuscated and unreadable, the heuristics and embedded URLs suggest a typical pattern of a malicious PDF dropper. The embedded JavaScript is likely responsible for downloading and executing a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9401

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
95cef0f54dc8bfc453f1a213f2fa83cafd97d86b76dd52d753158865c894eab6
pdf-javascript-stream PDF /JS object 12 at offset 0xA1F4 4067 bytes