Malicious PDF — malware analysis report

Static analysis result for SHA-256 68001b30bf9b56fc…

MALICIOUS

PDF

2.62 MB
MD5: 78872c6c87524e762cc7b7c796528ade SHA-1: 2bfb819440e1032650b4e9b628cbcf9b0f108181 SHA-256: 68001b30bf9b56fc94791f89701cc39eb529cc7b332d965dcc1aa5b9e3c4e8e4
84 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file is heavily obfuscated, indicated by the high stream count and the presence of encrypted content with JavaScript. The embedded JBIG2 streams are suspicious and likely used to conceal malicious code or a downloader. The PDF_ENCRYPTED_WITH_JS heuristic strongly suggests that JavaScript is used to decrypt and execute a payload, which is a common technique for delivering malware via malicious documents.

Machine Learning

  • Nyx PDF Classifier clean score 0.0005

Heuristics 5

  • Encrypted PDF carries /jS — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/jS). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JBIG2Decode filter medium PDF_JBIG2
    JBIG2 image decoder present — historically used in zero-click exploits
  • Unusually high stream count medium PDF_MANY_STREAMS
    PDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 32

Files carved from inside the sample during analysis.

FilenameKindSourceSize
jbig2_00_off00025181.bin
811613e35bab6b93e3c0ddccd988b2a729a4295fbc1347fb8e34b9114f222de3
pdf-jbig2-stream PDF JBIG2 stream at offset 0x25181 4433 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.
jbig2_01_off0002643c.bin
a21798a89a515f3a718eaebc6778f71d20c7f007a74d7f5c3e84160e101e8d23
pdf-jbig2-stream PDF JBIG2 stream at offset 0x2643C 4406 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.
jbig2_02_off000276df.bin
ece1710f61a7bce5dd6da20363149b148b51bab6fe61b4aae3a90ff790334d7f
pdf-jbig2-stream PDF JBIG2 stream at offset 0x276DF 4567 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
jbig2_03_off00028a22.bin
8c0316028f5176611967a5777430c2cbab3614224578efbb6b8980d4412cf0dd
pdf-jbig2-stream PDF JBIG2 stream at offset 0x28A22 4549 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
jbig2_04_off00029d54.bin
de5a33306ffcf478ff11455434751fb654570070ec976feae6813722b9511246
pdf-jbig2-stream PDF JBIG2 stream at offset 0x29D54 4920 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_05_off0002b1f9.bin
c8f10f49aae2cd6a4ef46b76a9a64c77a76a9dcd9fab87c65285326ca5e88bb9
pdf-jbig2-stream PDF JBIG2 stream at offset 0x2B1F9 5865 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_06_off0002ca4f.bin
f7f6c6d1180e63b344852e64f7b9d55608c8f8f0120dac8ff7c0848d8029bf5d
pdf-jbig2-stream PDF JBIG2 stream at offset 0x2CA4F 4541 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.
jbig2_07_off0002dd78.bin
c7cd41254677380acb13a3f1f6bead56f6588216be5a8f0002d08e6a293d1d02
pdf-jbig2-stream PDF JBIG2 stream at offset 0x2DD78 4277 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
jbig2_08_off0002ef99.bin
aec6e2469f0534df46aed379899e3ec71d262c05c87880935fbaa9dec0ac4d5b
pdf-jbig2-stream PDF JBIG2 stream at offset 0x2EF99 1019 bytes
jbig2_09_off0002f501.bin
e8550d8a362cf52b0ff5487412339619139fa6b01123def52077571419fef94d
pdf-jbig2-stream PDF JBIG2 stream at offset 0x2F501 4812 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
jbig2_10_off00030939.bin
d49385ec3bd2b0cb41ac47d6976e55e116d392b1581b5bfcdd7f32172cab3507
pdf-jbig2-stream PDF JBIG2 stream at offset 0x30939 934 bytes
jbig2_11_off00030e4b.bin
c2392250cbb03e9c2d916e7fa0d20f41b46632738663922a186b326bc51fd484
pdf-jbig2-stream PDF JBIG2 stream at offset 0x30E4B 4994 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_12_off0003233a.bin
93bc872ef676150dc86dc22fa7fe23832553fb766c58fefb70d0f0e6cc0bfc82
pdf-jbig2-stream PDF JBIG2 stream at offset 0x3233A 1020 bytes
jbig2_13_off000328a2.bin
7d9c29aab4af82a911bb7450bff73fed0c35d95f6f99cc174b06f841001c0db8
pdf-jbig2-stream PDF JBIG2 stream at offset 0x328A2 4449 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
jbig2_14_off00033b6e.bin
39470f27c21ccb1d4eb8c2cc3dce3f53ea8a01938276897264dc01d19b999434
pdf-jbig2-stream PDF JBIG2 stream at offset 0x33B6E 4380 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
jbig2_15_off00034df5.bin
f629d0822a6ae8dc31e466a25cb6daa349b3f8c138b01c2a0a78f6d315e6b447
pdf-jbig2-stream PDF JBIG2 stream at offset 0x34DF5 4530 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
jbig2_16_off00036112.bin
a1c0b759b33d5cb2b5bd37c1c07cfbd160b7202bedc95b1149d8d7b6fdec5846
pdf-jbig2-stream PDF JBIG2 stream at offset 0x36112 6178 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_17_off00037a9e.bin
432501c6349213db84989e65f35208e6afdf387a30f332a4836e16e55fd1b359
pdf-jbig2-stream PDF JBIG2 stream at offset 0x37A9E 5044 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_18_off00038fbc.bin
6788b8f4a276d3cd12971e2c92b368a7e909259678adb9f2f9f27b58a1970014
pdf-jbig2-stream PDF JBIG2 stream at offset 0x38FBC 5755 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
jbig2_19_off0003a7a3.bin
e2f9e2820fcbcb741a297c2360711c66173d0c6e4fcb2254e73db42e8d383e82
pdf-jbig2-stream PDF JBIG2 stream at offset 0x3A7A3 5293 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_20_off0003bdb9.bin
04967d6e81e86643703b2066286c1f79cae0fb32f29914637ea39b038420ac9f
pdf-jbig2-stream PDF JBIG2 stream at offset 0x3BDB9 5992 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_21_off0003d68c.bin
56b31a9824c909272f36dbf2b0f3c0156f37a6aef48dacd60020a978867317e1
pdf-jbig2-stream PDF JBIG2 stream at offset 0x3D68C 6094 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_22_off0003efc5.bin
affadb9acdc72c4883d64b1fa56b47e3f72cccf6daf1a876e0f864d879c0a92a
pdf-jbig2-stream PDF JBIG2 stream at offset 0x3EFC5 6577 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_23_off00040ae2.bin
79d7932b39bd41d7a39c7be41cda0e220f85661100e24dd63886f7b0c8533a7e
pdf-jbig2-stream PDF JBIG2 stream at offset 0x40AE2 5213 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_24_off000420a9.bin
1b4c5bcef6ac251078be0eca3439667b8608c3be0143c8dcf611a4a949cb2a49
pdf-jbig2-stream PDF JBIG2 stream at offset 0x420A9 6772 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
jbig2_25_off00043c89.bin
6e65b32aca20bfdb335a23a08f3b4109f5e8ae31d93255fa75b1fdb7492f0947
pdf-jbig2-stream PDF JBIG2 stream at offset 0x43C89 5157 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
jbig2_26_off00045219.bin
bc2e863574f7e96c87281ae0490ab876c5c248b0a71302cb6d52ef275b20465d
pdf-jbig2-stream PDF JBIG2 stream at offset 0x45219 2939 bytes
jbig2_27_off00045eef.bin
253a1dd91806e58b85c3e3b892d0ab9773c89c6bfa728aad185d6422ef65951c
pdf-jbig2-stream PDF JBIG2 stream at offset 0x45EEF 2729 bytes
jbig2_28_off00046b03.bin
64f65d77b93eca72c7c29d34ab95d808a37e64f29fc254504268f8c0ba1e442a
pdf-jbig2-stream PDF JBIG2 stream at offset 0x46B03 2779 bytes
jbig2_29_off0004774a.bin
71bc9b1635ef94c5234301d4cfa8abf626557b3d91f3d96889a28b27106a39a9
pdf-jbig2-stream PDF JBIG2 stream at offset 0x4774A 3209 bytes
jbig2_30_off0004853f.bin
088cb126c22e1ffcce4322eeeff6ac3817fc8c6df92f31044c4e534223be7ccc
pdf-jbig2-stream PDF JBIG2 stream at offset 0x4853F 3219 bytes
jbig2_31_off0004933f.bin
948306c4d657d08ec78cfff8c123c42a989761d1e236eafc3f86563d0847e3bf
pdf-jbig2-stream PDF JBIG2 stream at offset 0x4933F 3533 bytes