Malicious PDF — malware analysis report

Static analysis result for SHA-256 5282dd51542d1014…

MALICIOUS

PDF

6.8 KB Created: 2010-09-13 12:13:16 Authoring application: Qggewasdebo (via eeaf8Casiwajiomidox)
MD5: dbd965751a5a767917fd30873ef7a6cf SHA-1: e9dfe27ab4910b50795ea33847c5acd46994126a SHA-256: 5282dd51542d10147bc2777be0b459f08d3f593320b0861574ecb0d0f7ed25af
146 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains embedded JavaScript, flagged by multiple heuristics as obfuscated and malicious. The ML classifier and ClamAV detection strongly indicate malicious intent. The JavaScript action and embedded JS stream suggest the document is designed to execute arbitrary code, likely to download and run a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9933

Heuristics 4

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • Page-word XOR JavaScript eval stager high PDF_PAGE_WORD_XOR_EVAL_STAGER
    PDF JavaScript enumerates rendered page words with getPageNthWord/getPageNumWords, extracts encoded byte fragments, XOR-decodes the stage with char-code helpers, and evals the result. This is an old exploit-kit staging pattern and is not normal document JavaScript.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
4ed0e25cb988f785847231ed349ce1e5f2b9cb2b6f573c0a3462080817722f94
pdf-javascript-stream PDF /JS object 11 at offset 0x1301 1732 bytes