Malicious PDF — malware analysis report

Static analysis result for SHA-256 548470123406b5d0…

MALICIOUS

PDF

3.5 KB
MD5: b1a348b53e3b5ef65fb90c8f1be8a070 SHA-1: 5c1ab377618368d8cf771dfd0ff84eda765fb0f6 SHA-256: 548470123406b5d052de0b481acfa3067168cb2c604c5940a811678297bb5bd5
96 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.002 Spearphishing Attachment T1190 Exploit Public-Facing Application

The PDF contains obfuscated JavaScript and uses ASCIIHexDecode filters, indicating an attempt to hide malicious code. ClamAV detection confirms its malicious nature. The primary attack vector appears to be exploiting PDF vulnerabilities to execute embedded JavaScript, likely for further payload delivery.

Heuristics 4

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • ASCIIHexDecode filter (with exploit indicators) medium PDF_FILTER_HEX
    Hex-encoding filter present alongside exploit delivery indicators — often used to hide payload or shellcode bytes
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.