Malicious PDF — malware analysis report

Static analysis result for SHA-256 6847450e2d962068…

MALICIOUS

PDF

6.7 KB Created: fú7Vԕ&–)ÞÆô|õIâ Authoring application: q£w†Øeƒ)ÄÅí|ãIç (via q£w†ØeƒH®°ã¤§}—§Á:‘à0æRÀT)
MD5: cf2d2ce8d3bac6883e378d7faab45492 SHA-1: 94917b2ec561a8487e374867b7c7aba3c0a35f7b SHA-256: 6847450e2d9620685a9136d1c505b8d28c958bb3b5e07c8d4d6b3526a826a33c
88 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment T1140 Deobfuscate/Decode Files or Information

The PDF contains embedded JavaScript, flagged as malicious by ML classifiers and heuristics. This script is heavily obfuscated but appears to construct a URL for downloading a second-stage payload. The PDF is encrypted and uses an OpenAction to trigger the JavaScript, indicating an attempt to hide malicious activity from static analysis.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0024_001.js
268afc0e43f15e6a3a7714128918ded644507a797ddae3efe75d10b478f1e5e4
pdf-javascript-stream PDF /JS object 24 at offset 0x8CF 7346 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 5 long base64-like blob(s).