Malicious PDF — malware analysis report

Static analysis result for SHA-256 2ef53ef137bcdb0b…

MALICIOUS

PDF

10.4 KB
MD5: aa70783940922990cd5cb1ebb5f3f0ba SHA-1: 73ddd8fd29be195682a05f943f4acc3146ee7fcd SHA-256: 2ef53ef137bcdb0bbfbc61c813f0d76688b1f2de885551d65aba82e894b2b49f
78 Risk Score

Malware Insights

MITRE ATT&CK
T1555 Credentials from Password Stores T1059 Command and Scripting Interpreter

The PDF file was flagged by ClamAV for having an obfuscated object name, a common technique for hiding malicious content. Static triage also identified a suspicious embedded file. The document body is heavily obfuscated and unreadable, suggesting it is not intended for human consumption but rather to exploit vulnerabilities or deliver a secondary payload via the embedded artifact.

Heuristics 4

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0001.bin
3b36a500caa4b454a4ff19a607d0a71e78cbf1106e23191dd58e30b23da74e20
pdf-embedded-file PDF EmbeddedFile object 1 at offset 0x86 13408 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).