Malicious PDF — malware analysis report

Static analysis result for SHA-256 4291487a8e2dc337…

MALICIOUS

PDF

37.3 KB Created: ;ftQÙª(ƒŸ»Ó3w‡º%Û5Uy; Authoring application: £6`›šz²È‹—/¶ü (via £6`›šp²Í‹–#¶ëJ)
MD5: 6d920b3310f8fc68da671eda95cb11da SHA-1: 81b2254d4604a2a1b4b657dc33b26dae92fed12a SHA-256: 4291487a8e2dc33757af292ba7ebcca36d2b4af4abe734a538acd412ca3188f2
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment

The PDF file is encrypted and contains JavaScript, indicating an attempt to obscure malicious content. The embedded JavaScript stream, named 'javascript_obj0009_000.js', is likely responsible for executing the payload. The presence of JavaScript actions and encryption points towards a social engineering lure designed to bypass static analysis and deliver a malicious payload.

Heuristics 4

  • Encrypted PDF carries /JavaScript — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/JavaScript). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0009_000.js
97f3a8600f9bdb35b21698b517493e57a4865020f962d4e7eb528849eb48684b
pdf-javascript-stream PDF /JS object 9 at offset 0x3BE 35550 bytes