Malicious PDF — malware analysis report

Static analysis result for SHA-256 3584901ae8a67581…

MALICIOUS

PDF

7.4 KB Created: 2010-09-16 18:55:19 Authoring application: Tolhipezorojpagiwaqo (via 28c96Seueganadazaqeav)
MD5: 7c448b1583519646a81db72ed9752d04 SHA-1: 100b707da3cb8a58620dcd9fbe2625952498f3af SHA-256: 3584901ae8a675819e3f2a90f07a4eaa963d304b7f8cbbd1d0365c220cb1d0e2
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1027 Obfuscated Files or Information

The PDF file exhibits characteristics of malicious intent, specifically through the presence of obfuscated JavaScript. The ClamAV heuristic 'Heuristics.PDF.ObfuscatedNameObject' strongly suggests malware. The embedded JavaScript, though truncated, is likely responsible for executing a malicious payload, contributing to the overall attack pattern of delivering and running harmful code. The obfuscation itself is a technique to evade detection.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
e2d41866c9fb013feb60cefe8b41892c7277decb0774febb940ce493b1221654
pdf-javascript-stream PDF /JS object 11 at offset 0x1387 2332 bytes