Malicious PDF — malware analysis report

Static analysis result for SHA-256 5876bf83adc7d332…

MALICIOUS

PDF

1.9 KB Authoring application: sli
MD5: 52bd9e935123e97a8a9ebbaff31e27c0 SHA-1: 7c62c8a48f21d1ab8d35d9511645b61a047d94a2 SHA-256: 5876bf83adc7d332aa7dff761198214a88c7c35273b41ed778d707fd3cd7b4aa
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The ClamAV detection 'Pdf.Exploit.Dropped-91' strongly suggests this is an exploit-laden document. The deobfuscated JavaScript file is the primary artifact for further analysis, likely containing the exploit code or a downloader. The attack pattern is inferred from the exploit detection and the presence of JavaScript, suggesting a drive-by download or similar exploit delivery.

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-91 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-91
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
8373a8ab1ae91eb8da74836afbdce44166344fa5519f2b3ddff890aaee5fbb0a
pdf-javascript-stream PDF /JS object 76 at offset 0x426 548 bytes
deobfuscated.js
b4617358408665031cd5619721dad132a8d2f7cfaa45875d4b921b499c7832b7
deobfuscated-js PDF JavaScript deobfuscation pass 1213 bytes