Malicious PDF — malware analysis report

Static analysis result for SHA-256 4a4bc271708f2ece…

MALICIOUS

PDF

45.5 KB
MD5: a8a2784aa752bdd95e4ffab9586e4902 SHA-1: 4aa64e8358e205c19b1231964e4b2af380ca6c12 SHA-256: 4a4bc271708f2ecee4f6b26aea9ab6e54073f921d71c1f9777468a2ba8a2ab4b
114 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF document was flagged by multiple heuristics, including ClamAV's 'Heuristics.PDF.ObfuscatedNameObject' and an ML classifier, indicating malicious intent. Embedded JavaScript, though obfuscated, is present and likely responsible for the malicious behavior. The presence of XFA form elements further suggests a complex, potentially exploitative structure. The confidence is moderate due to the obfuscation of the JavaScript, preventing a definitive analysis of its exact function.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9926

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
3f757c7e633c53e43256a1b04fe8cfa4447ddc7c2b16a76c3a4fcdc833121398
pdf-javascript-stream PDF /JS object 12 at offset 0xA1FF 3830 bytes