Malicious PDF — malware analysis report

Static analysis result for SHA-256 2dbd28a302a13b0f…

MALICIOUS

PDF

7.2 KB
MD5: 893e2bb88512655d00cf7a93c6ac6bf5 SHA-1: 80af62b238f0d11d2b4eda0f0e7a6f8fb8b8b65f SHA-256: 2dbd28a302a13b0f165b7b3cb2e044610f8a4d940d8e9c9115ee77b0de628847
124 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment

The PDF file exhibits multiple indicators of malicious intent, including embedded JavaScript and RichMedia (Flash) content, flagged by critical and high severity heuristics. The ClamAV detection 'Heuristics.PDF.ObfuscatedNameObject' strongly suggests malicious obfuscation techniques. The embedded JavaScript, though obfuscated, appears to be designed to execute further malicious code, likely exploiting vulnerabilities within the PDF reader or Flash player.

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload