Malicious PDF — malware analysis report

Static analysis result for SHA-256 64deb0a9c54ea33e…

MALICIOUS

PDF

6.21 MB Created: &T+Ёƒ;'Œ0MÑî0 Authoring application: N'KÏÖÞÔSe7/NÒî
MD5: 212ea9d1cbc3e7d733dc73282a061c20 SHA-1: 6200e1e6341d13cc4ee7a596f4f016eabc44b52e SHA-256: 64deb0a9c54ea33e74e5013c34dc008a5684215286231901c26e9daa0236179c
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1055.001 Process Injection T1027 Obfuscated Files or Information

The PDF is encrypted and contains an /OpenAction, indicating that its payload is hidden from static analysis and likely executed upon opening. High stream counts and the presence of JBIG2 encoded streams suggest obfuscation techniques are being used to conceal malicious content. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6103

Heuristics 6

  • Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JBIG2Decode filter medium PDF_JBIG2
    JBIG2 image decoder present — historically used in zero-click exploits
  • Unusually high stream count medium PDF_MANY_STREAMS
    PDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/

Extracted artifacts 32

Files carved from inside the sample during analysis.

FilenameKindSourceSize
jbig2_00_off000021ab.bin
cbffd3964423edf09c7f242aebef6d3f63aedb73d3d71ee8e22a918689574340
pdf-jbig2-stream PDF JBIG2 stream at offset 0x21AB 39570 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
jbig2_01_off0001ee9b.bin
b67070970f4bdfadba817ea9073cd6b172e0de62e21a70b666d88897fa27f9a5
pdf-jbig2-stream PDF JBIG2 stream at offset 0x1EE9B 101 bytes
jbig2_02_off0001f116.bin
f4cf5148fbbbd76da901c97ee1cbffd28f3bdbe43c5ce555d3d67a8f39065095
pdf-jbig2-stream PDF JBIG2 stream at offset 0x1F116 3219 bytes
jbig2_03_off0001ff17.bin
bbdc51f493e4af3cba62b9611297c044dea34691c4b4698721d48829ece91c34
pdf-jbig2-stream PDF JBIG2 stream at offset 0x1FF17 101 bytes
jbig2_04_off0002046f.bin
a495c926258045fb211a98367e7e9baa9650b0f7255c0e39d067d540323d4913
pdf-jbig2-stream PDF JBIG2 stream at offset 0x2046F 7432 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
jbig2_05_off00022a0e.bin
0ac0f279d9619987eccde9115a15e9950c0e97dd246311823fd8b487e18f0f6f
pdf-jbig2-stream PDF JBIG2 stream at offset 0x22A0E 7673 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_06_off000256ad.bin
ff5f2f29a55ae77bf0414ab006979f7254b5472035fd93f9c4bbbf5fd879c2d4
pdf-jbig2-stream PDF JBIG2 stream at offset 0x256AD 13139 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_07_off00033b8c.bin
3d65e766866dd0163d0aefadd979b60297f86ff5f06f8dbf75e1bc9ef14e1de1
pdf-jbig2-stream PDF JBIG2 stream at offset 0x33B8C 14831 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_08_off0003ed80.bin
91b12eeabea68fadd79f40d424875992a7369b2b134c755b6c44e49da1a3b3f8
pdf-jbig2-stream PDF JBIG2 stream at offset 0x3ED80 14266 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_09_off00042c15.bin
17b2101290d6c0068238fbe96574fbf9c3ac044a1264d2d97e2bb41da37cd35c
pdf-jbig2-stream PDF JBIG2 stream at offset 0x42C15 5413 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.
jbig2_10_off0004481c.bin
f4d938a568ce6726e1a18099f069fcc60b36176052bcc2e94e5e7f5470860f7b
pdf-jbig2-stream PDF JBIG2 stream at offset 0x4481C 8311 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_11_off000471fe.bin
925b10cd1b7d8b69847fcd342099e43adfcd149289b6fa49b8fd7da8d36d458c
pdf-jbig2-stream PDF JBIG2 stream at offset 0x471FE 10218 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_12_off0004a32f.bin
5e059596dbca7c0b175076444cabba4e103e911752c72e378570371fe4ca2ea4
pdf-jbig2-stream PDF JBIG2 stream at offset 0x4A32F 9695 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_13_off0004d222.bin
9512e27b25489bdeefe93afe7c769d099107521869c08e3738feb234ad609f89
pdf-jbig2-stream PDF JBIG2 stream at offset 0x4D222 10600 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_14_off00050480.bin
804f8b996a1bd024dabb76e8e7c2603a444bbc7918af26fd443d6033cc201f76
pdf-jbig2-stream PDF JBIG2 stream at offset 0x50480 10056 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_15_off00053499.bin
55759471ec9cd77079c1c10fa6222639ad2ebd271c1016dc7dbe4356ada7db36
pdf-jbig2-stream PDF JBIG2 stream at offset 0x53499 9934 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_16_off000565a8.bin
d3662652aa9851e27cb3445c368ce7ba57cf052cbec1be742c7ee7bc24a990fd
pdf-jbig2-stream PDF JBIG2 stream at offset 0x565A8 9989 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_17_off000590d8.bin
9ee270917990d880915e9e44bd90601904b1dcc8e1ef981ae1d9cac1aefdaec2
pdf-jbig2-stream PDF JBIG2 stream at offset 0x590D8 4735 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.93, consistent with packed or encrypted content.
jbig2_18_off0005ad23.bin
883247e8e8db0bb03c6f020a061f0f30c010dfcf5d0ed84fe82c6cf5a19d57ce
pdf-jbig2-stream PDF JBIG2 stream at offset 0x5AD23 8821 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_19_off0005d350.bin
01086ba4fd062979185ef459799a3d95387d2a550e976d4d46b309d30e6e4105
pdf-jbig2-stream PDF JBIG2 stream at offset 0x5D350 3558 bytes
jbig2_20_off0005eb9a.bin
961662a92703daf6f297bd9f5ea5f1cdeb72a13dd1ca0f8711ec88926b026c60
pdf-jbig2-stream PDF JBIG2 stream at offset 0x5EB9A 9594 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_21_off00061dad.bin
e0fcf52df3d0e19fead4b8cb6c23d85446c3035429db18386309e16efbf4e9c1
pdf-jbig2-stream PDF JBIG2 stream at offset 0x61DAD 11497 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_22_off00065310.bin
12937083c89cb8eef3e93dda7d544fcdd523c37658f890619329d952e40ad00d
pdf-jbig2-stream PDF JBIG2 stream at offset 0x65310 6999 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
jbig2_23_off00066fdb.bin
ecc801f97caf72007787081a1d2af8e0bb977e7caa382ceb2b7273ee2c966616
pdf-jbig2-stream PDF JBIG2 stream at offset 0x66FDB 193 bytes
jbig2_24_off00067fdb.bin
7647a0517a465c35a8e55da4d65b95ba447fd605d6cac00461ec77a39085a718
pdf-jbig2-stream PDF JBIG2 stream at offset 0x67FDB 15040 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_25_off0006bf55.bin
f19c0a33633582a1cf6748061bfe592bb3bdcbc0fb359661a519badebd36a15d
pdf-jbig2-stream PDF JBIG2 stream at offset 0x6BF55 4610 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.93, consistent with packed or encrypted content.
jbig2_26_off0006d7c2.bin
1e25f52629260e3ca08242003d9523e123ccd4990fb0d2edcd0900fc868b03f5
pdf-jbig2-stream PDF JBIG2 stream at offset 0x6D7C2 7050 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_27_off0006f4c0.bin
d3e7bb9b1a9af9ed525c9e4fe5c4bfeb553cf509da88d69e930bc0ea409764ad
pdf-jbig2-stream PDF JBIG2 stream at offset 0x6F4C0 192 bytes
jbig2_28_off000703fc.bin
ef14fef307575c89aef0d7095772ff0ac9864c371bcd457f370963c98cde0d66
pdf-jbig2-stream PDF JBIG2 stream at offset 0x703FC 14164 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_29_off00074ae6.bin
fd575ab19a9eb2bcc3ffd16df38f79369f3346f1d601db3f3d9ca4821af270f0
pdf-jbig2-stream PDF JBIG2 stream at offset 0x74AE6 14860 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
jbig2_30_off000796e0.bin
77f410aa86424ad5f3670249f743ad0d6a08b30b3aaba2ee3b5f9772e0daf6b3
pdf-jbig2-stream PDF JBIG2 stream at offset 0x796E0 16604 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
jbig2_31_off0007d92f.bin
b23ea51823cce72e52644c330330d1d34e58605df2997834bbad878b9e5b49e8
pdf-jbig2-stream PDF JBIG2 stream at offset 0x7D92F 197 bytes