Malicious PDF — malware analysis report

Static analysis result for SHA-256 3eef9f8360f0422e…

MALICIOUS

PDF

7.6 KB Authoring application: Qimigiwova (via 268deBashemeriwesohitaro)
MD5: 3886f0b511bf6af186230ee24b8e96aa SHA-1: 47ef7a09f99c82b2d8a4e4ebd335aae997512230 SHA-256: 3eef9f8360f0422e1e341fae8facd269a8868f26d0f90d712e477de751920728
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment

The PDF file was flagged by multiple heuristics, including a critical ClamAV detection for obfuscated objects and an ML classifier indicating maliciousness. The presence of embedded JavaScript, identified as 'pdf-javascript-stream', strongly suggests an attempt to execute malicious code upon opening. While the exact script functionality is obscured, its presence is the primary indicator of malicious intent, likely for downloading and executing a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0010_000.js
ed31b16df2b6492a4d5be85b534deca964c2f0e07a8443782787f4ed9c62c93c
pdf-javascript-stream PDF /JS object 10 at offset 0x1303 3192 bytes