Malicious PDF — malware analysis report

Static analysis result for SHA-256 511ba25cbbe4aa34…

MALICIOUS

PDF

414.0 KB Created: 2010-03-13 04:47:25 +02:00 Authoring application: Adobe InDesign CS4 (6.0) (via Acrobat Distiller 9.0.0 (Windows))
MD5: 4cb7bab3a24a39a6a4dc2d0a342b41c1 SHA-1: 46828cefa1c6b3fd43c3ed7a4cea14a67cb3288c SHA-256: 511ba25cbbe4aa343deb6b045a71fa6632268e66039c185c49be3dcfd224a474
78 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1027 Obfuscated Files or Information

The PDF file contains embedded JavaScript, which is obfuscated using unescape() calls and hex escape sequences. This script is likely designed to download and execute a second-stage payload. The document body consists of metadata and does not provide a clear lure, but the presence of obfuscated JavaScript strongly suggests malicious intent.

Heuristics 6

  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 1 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj7064_000.js
5c95ddfbe16b63eebf455803314f180a2eb8ac0c23a6abbeefe4c5c96bc6518a
pdf-javascript-stream PDF /JS object 7064 at offset 0x43EF7 31531 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 4 long hex-escaped blob(s).