Malicious PDF — malware analysis report

Static analysis result for SHA-256 4fdafe675c94f88e…

MALICIOUS

PDF

34.8 KB Created: èÊ ò8²nÿ)ÊSœ˜‹‡%ݑì Authoring application: RÂøSÃz>à_®¯D’gÝ (via RÂø@Ãz>ê_«¯EžgʳÉ)
MD5: 333cf0425c25e349a426385632db0b65 SHA-1: 3afaaaa7e1f8100d36b54a85b2e3cb72819b5af3 SHA-256: 4fdafe675c94f88e775d9b73267f63f8f09aface99568c4260cf7b77135b1eeb
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1027 Obfuscated Files or Information

The PDF file is encrypted and contains embedded JavaScript, indicating an attempt to obfuscate malicious content. The JavaScript stream, named 'javascript_obj0009_000.js', is likely responsible for executing the hidden payload. The presence of JavaScript actions and encrypted content points towards a technique to bypass static analysis and deliver a malicious payload upon opening.

Heuristics 4

  • Encrypted PDF carries /JavaScript — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/JavaScript). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0009_000.js
33ebd9b03376b559285a967ebb7ba32e3bb0d67c29b8da1488d8a0be4e54d2bf
pdf-javascript-stream PDF /JS object 9 at offset 0x3DA 32898 bytes