Malicious PDF — malware analysis report

Static analysis result for SHA-256 330de06d28fa787b…

MALICIOUS

PDF

45.2 KB
MD5: 8a57fdf01e96b5f04bb80c28d81899a1 SHA-1: 71454a898e7fd51094231e4c6c1948409f04aa62 SHA-256: 330de06d28fa787bbfc3a1fc698aa7a472c3891d14289d1afebf08a9d16af217
84 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1027 Obfuscated Files or Information

The PDF file exhibits characteristics of malicious intent, including embedded JavaScript and XFA form elements, which are often used to deliver exploits or malware. The ClamAV heuristic 'Heuristics.PDF.ObfuscatedNameObject' strongly suggests obfuscation techniques are in play. While the document body is unreadable, the presence of JavaScript points towards an attack pattern involving script execution. The embedded JavaScript stream, though not fully analyzed here, is the primary mechanism for potential malicious activity, likely downloading and executing a second-stage payload.

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
7a00f9f65f6d84dbb4cf2e8246c98d99bf148c01ababa8b0c7b12c86b29afc4b
pdf-javascript-stream PDF /JS object 12 at offset 0xA1E0 3532 bytes