Malicious PDF — malware analysis report

Static analysis result for SHA-256 33508991fca18506…

MALICIOUS

PDF

7.4 KB Created: 2010-09-16 18:55:19 Authoring application: Tolhipezorojpagiwaqo (via 81a82Seueganadazaqeav)
MD5: 883e6d4bf13cd26d8bee84a54b259cad SHA-1: a31456d1759276cdf1b2298b75a982ea191ed912 SHA-256: 33508991fca18506c3f6512872e6848ae728df00852cecccf02ffa55a6d0b279
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment

The PDF file exhibits characteristics of malicious intent, including the presence of obfuscated JavaScript. The ClamAV heuristic firing further supports this assessment. The embedded JavaScript is likely designed to download and execute a secondary payload, a common technique for initial compromise. The exact nature of the payload and its ultimate goal cannot be determined from the provided evidence.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
e2d41866c9fb013feb60cefe8b41892c7277decb0774febb940ce493b1221654
pdf-javascript-stream PDF /JS object 11 at offset 0x1387 2332 bytes