Malicious PDF — malware analysis report

Static analysis result for SHA-256 638c8fbb719acfaf…

MALICIOUS

PDF

44.9 KB
MD5: 372db1e6f39b1d42ee64b3f0e27b25c4 SHA-1: 5a88d14f976341049ecdfd2efa8c0f59b3912416 SHA-256: 638c8fbb719acfaf3f970f34cfe90cc866525899efa1fcff7ee7eabb3720d036
176 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF sample contains embedded JavaScript, identified as a PDF JavaScript exploit cluster. This script is likely responsible for downloading and executing a second-stage payload, as indicated by the exploit cluster heuristic and the presence of obfuscated JavaScript code. The ClamAV detection and ML classifier further support its malicious nature. The benign URLs extracted are not indicative of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9364

Heuristics 6

  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
56665d2c35b941412ae83fdb121dff3c369622dc521637d1edb991067835222c
pdf-javascript-stream PDF /JS object 12 at offset 0xA1ED 3366 bytes