MALICIOUS
116
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1204.002 Malicious File
The PDF file exhibits multiple heuristic firings indicating malicious intent, including embedded JavaScript and a suspicious secondary embedded PDF. The ClamAV detection 'Heuristics.PDF.ObfuscatedNameObject' strongly suggests malicious content. The presence of JavaScript actions and streams points to code execution capabilities within the PDF, likely for delivering a secondary payload.
Heuristics 5
-
ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTIONClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
-
Secondary embedded PDF body has suspicious static findings high POLYGLOT_CHILD_PDF_STATIC_TRIAGEA valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/xap/1.0/
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/pdf/1.3/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0006_000.js03af9b3d8b31cddcea24ffe9810cb9c380e7051612e468b87347aba1d0214420 |
pdf-javascript-stream | PDF /JS object 6 at offset 0x18B | 6710 bytes |
stream_007_off000197cf.bin7cd525d273482f57dd75642dfe72fbd3b33facd66905175f57c1f616a9f2a077 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x197CF | 1000 bytes |
polyglot_child_pdf_off0001887f.pdf268ddd6857b789c3455f43c4cb15ea0f23cecff3d656975b88e7163864b405de |
polyglot-child-pdf | Secondary PDF body inside pdf container at offset 0x1887F | 12656 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.