Malicious PDF — malware analysis report

Static analysis result for SHA-256 3474f2c7267748d5…

MALICIOUS

PDF

6.7 KB
MD5: cb2c7685a33fc0451f7e95f53ff53b1e SHA-1: 030731f0e4a6c07634f0e0db98977c3f55000dbe SHA-256: 3474f2c7267748d5a22ab84fee25e559f9c36da1f630b35e8ca7e8b40584f834
66 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.002 Spearphishing Attachment

The PDF contains embedded JavaScript, flagged by multiple heuristics, which is designed to execute and likely redirect the user to a malicious URL. The ML classifier strongly indicates malicious intent. The obfuscated JavaScript is designed to obscure its true purpose, but the presence of an embedded URL and the ML score suggest a malicious download or redirection attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www1.stronglfoantivir.uni.me/?8s3ygb02j=XNag3aTHqJeQ6N3WrKOdnJ2V1eLgpqua1G2nZq%2BglWZpkOfnr6ChmpyYopelpaKc1eV1pWaqjcOSlNywxsa6lNfVyqyUlOeN

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0005_000.js
b75da86a189654d65e4edb38f1fbf2df9dbd5f6dc5df40570eec43aeee9765b0
pdf-javascript-stream PDF /JS object 5 at offset 0x1D4 6076 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s). Carved artifact contains 1 long hex-escaped blob(s).
javascript_obj0005_001.js
689dabe90ee21f4fb5bc62d38e6665d00a96c34f5cd1df9cf001be22f8bbd253
pdf-javascript-stream PDF /JS object 5 at offset 0x1F7 6359 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s). Carved artifact contains 1 long hex-escaped blob(s).