Malicious PDF — malware analysis report

Static analysis result for SHA-256 6681a2716789158a…

MALICIOUS

PDF

6.6 KB Created: U‡í§£ÅgÅ¿ÉdèšÛß Authoring application: BÞ­þñˆ$׿ Êè†ØÔ (via BÞ­þñˆ$×Þg¿q—Á‹”“QÖ_úN„V*b)
MD5: a1431db3ab8933bd18a1d6da3b109637 SHA-1: b3bb85857a8343866568f1d5ce9c36173b27105e SHA-256: 6681a2716789158a51bd0b2789fce5c7308a5b66c772a09eeb5909b55b45f7f7
88 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0024_001.js
9955264009f52a0ade626ffefbda7929d778ad67356dd5794d49d2a4fdcc5ee3
pdf-javascript-stream PDF /JS object 24 at offset 0x8CD 7052 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 8 long base64-like blob(s).