Malicious PDF — malware analysis report

Static analysis result for SHA-256 32c3c9acf8d2cf6d…

MALICIOUS

PDF

7.3 KB Authoring application: Vttiikanaxe (via 23d33Qilionenz)
MD5: 77d348b52c3b8bbf7c771857ac5eb8e0 SHA-1: 012ead2956c8e87abe5ad7d4e2a7afd8a6f485d3 SHA-256: 32c3c9acf8d2cf6d19d735594d51b8b75152b5b2ec8fc6f35f6720d6b28f6018
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The ClamAV detection of 'Heuristics.PDF.ObfuscatedNameObject' further suggests malicious intent. The embedded JavaScript is likely responsible for executing the malicious payload, although its exact function is obscured. The document body is unreadable, providing no further context.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
001403b162f8dbcf8530ebd3eaa342e22031ed337de4856fe4d322bd6f869fb8
pdf-javascript-stream PDF /JS object 11 at offset 0x1328 2201 bytes