Malicious PDF — malware analysis report

Static analysis result for SHA-256 7201dcb82ceb8298…

MALICIOUS

PDF

7.5 KB
MD5: 0f30938d4baa9c3717db4e0617984dad SHA-1: 5b3bc3db99b3e7d1f3776ea3bee897ec82839cb1 SHA-256: 7201dcb82ceb8298ad2b00c241787b39fe7c0a512a9d628fc1d1ad5330e85693
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file was flagged as malicious by both ClamAV and an ML classifier. It contains embedded JavaScript, indicating an attempt to exploit PDF viewer vulnerabilities for client execution. The presence of JavaScript suggests the document is designed to download and execute a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PSSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.