Malicious PDF — malware analysis report

Static analysis result for SHA-256 6c544f8ba8c722ad…

MALICIOUS

PDF

7.4 KB Created: 2010-09-16 18:55:19 Authoring application: Tolhipezorojpagiwaqo (via ea3f1Seueganadazaqeav)
MD5: 8f5e761502f14499c02713b35a79ff95 SHA-1: 309192f6542a6e4d5946a1178167545c75b7a56f SHA-256: 6c544f8ba8c722ad766bf082621a2515d2a74893877477f3b735ed64e5c7e03d
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript, flagged by multiple heuristics and a ClamAV detection for obfuscated objects. The ML classifier also strongly indicates maliciousness. The JavaScript code appears to be obfuscated, but its presence and the PDF structure suggest it's designed to execute arbitrary code, likely downloading a further stage. The primary IOC is the embedded JavaScript file itself.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9954

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
e2d41866c9fb013feb60cefe8b41892c7277decb0774febb940ce493b1221654
pdf-javascript-stream PDF /JS object 11 at offset 0x1387 2332 bytes