Malicious PDF — malware analysis report

Static analysis result for SHA-256 5af4c3999c55d2d2…

MALICIOUS

PDF

19.8 KB Created: ƒÆZóU õÖÜ^hvlؙc;°ÀT° Authoring application: 9h”eCňìX+]E (via 9hŒeAńìX]QêÈHböôð—<ÜE=]š>T0؂Iÿ)
MD5: 2e651882339fc02163f6ef305fa2eb6a SHA-1: 7e6ec650710200de8c87ce75adc10d6a79c684d9 SHA-256: 5af4c3999c55d2d2c0de257e1148fefa45ef7f75c1107e689a5e917efc431612
86 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1027 Obfuscated Files or Information

The PDF file was flagged as malicious by an ML classifier and contains embedded JavaScript. The JavaScript action and embedded JS stream indicate that the document is designed to execute code. The PDF is also encrypted with JavaScript, suggesting the payload is intentionally hidden from static analysis. The primary attack pattern involves obfuscating malicious content within the PDF to evade detection and deliver a payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
5f6d9ac23597b514ac78dd60725018b4a3a11d175667d8a347dfc8f0db2f30bc
pdf-javascript-stream PDF /JS object 12 at offset 0x35F0 5150 bytes