Malicious PDF — malware analysis report

Static analysis result for SHA-256 45880a2523c319a8…

MALICIOUS

PDF

7.5 KB
MD5: 0d47453dc9cb9e85cbd894cd3a19416d SHA-1: 834faf088e3a092aea16dabe9508e1c85267c183 SHA-256: 45880a2523c319a894eaaee74450f646250b6852346baebb0bfdf0899556d310
78 Risk Score

Malware Insights

The PDF file contains embedded and obfuscated JavaScript, as indicated by the PDF_JAVASCRIPT and PDF_JS heuristic firings. ClamAV also flagged this as Heuristics.PDF.ObfuscatedNameObject, suggesting malicious intent. The JavaScript is likely responsible for executing the malicious payload, although its exact function cannot be determined without further analysis. The document body is minimal and does not provide additional context.

Heuristics 4

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PSSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.