Malicious PDF — malware analysis report

Static analysis result for SHA-256 31a7a28bd20a582d…

MALICIOUS

PDF

65.9 KB
MD5: ae9b93c34f3dcbb044ee31d4c1b912f6 SHA-1: 4afc95b1947fe5859badd73951768d1f24762aaf SHA-256: 31a7a28bd20a582de52edfedc68a58f3636166d8ec2b75d2c7bf68c1b2a3aaac
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by ClamAV for obfuscated JavaScript. The embedded JavaScript, although obfuscated, is indicative of a downloader attempting to fetch and execute a secondary payload from a remote URL. The presence of JavaScript actions and embedded JS streams strongly suggests malicious intent. The document body is heavily obfuscated and does not provide clear user-facing content.

Heuristics 4

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.bitstream.com