Malicious PDF — malware analysis report

Static analysis result for SHA-256 622ea2abfdc60795…

MALICIOUS

PDF

6.7 KB
MD5: 5fd6ccc0195725f9c5cd0066f03c2736 SHA-1: 7e607c2b9d5edc8b6b4e89b9b4da89e0195f3823 SHA-256: 622ea2abfdc607957fd9d1a2ab9f2324a0576f533b81fd372c7d939866bf7115
68 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript that is obfuscated but appears to be designed to download and execute a payload from a remote URL. The ML classifier and static triage heuristics strongly indicate malicious intent. The embedded JavaScript is responsible for contacting the external URL to fetch and execute the next stage of the attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www1.hardcleaneredd.uni.me/?os0ttlo3yw=k9ad2LHR55if7NHFr5mZoJaH4tneopyV1Khkp6mloWrendzUr5WWn5WUoJWolZaK2%2BZtpqidlZTb2dqexLiuktXK0qKli9eI

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0005_000.js
43ac696fee325adcb314d117dd830259ff9c3a0f6e078d305177631fda71f88e
pdf-javascript-stream PDF /JS object 5 at offset 0x1D4 6075 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s). Carved artifact contains 1 long hex-escaped blob(s).
javascript_obj0005_001.js
249d294aaf77c141fe4fbc1baa923e69b9b2bd888c96113966c67ded872020cc
pdf-javascript-stream PDF /JS object 5 at offset 0x1F7 6358 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s). Carved artifact contains 1 long hex-escaped blob(s).