Malicious PDF — malware analysis report

Static analysis result for SHA-256 379b41e3fd94f48d…

MALICIOUS

PDF

37.7 KB Created: 2025-11-23 22:00:10 UTC
MD5: a3c11ef580b554b35231843b2124fd29 SHA-1: df68fc6ff06d12c8e2ff06e0ea737c7ad3e5289e SHA-256: 379b41e3fd94f48d3f1756202fc4e702a98af4f01ca59b1be30cb3e31bc4b3ce
68 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains embedded JavaScript and is structured as an image-only lure, typical of phishing campaigns. The ML classifier strongly indicates maliciousness. The embedded JavaScript likely attempts to redirect the user to one of the provided URLs, which are designed to appear as legitimate invoices but are likely malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9935

Heuristics 5

  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 37 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bookingc.netlify.app/#invoice-1617964062.pdf
    • https://bocking.netlify.app/#invoice-1645080830.pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0005_000.js
578fc8de6e928a575e0bbea33f45500a773ce9654d4069132b7d7e759cc50c6b
pdf-javascript-stream PDF /JS object 5 at offset 0x169 70 bytes