Malicious PDF — malware analysis report

Static analysis result for SHA-256 73662393aaf2b00c…

MALICIOUS

PDF

6.6 KB Created: ®È¡¢pcléÿ¼Ì*ð3¹ Authoring application: ¹‘áû"./ éç¿Ó,ë7¿ (via ¹‘áû"./ ˆÊÝS¬dÿ-ÈæŠ;Ó}«Ì)
MD5: 50892d7b6b464da87ec77193b4b60fac SHA-1: bc555ffe06754e73e3e56d3adc759be11a936bc1 SHA-256: 73662393aaf2b00cba87b9e2a15a0626abd759301c73e40ed83817ebba338a40
88 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0024_001.js
a75b984ec34bd7d0740de5b070bd3b9d744e755c1a39ae1aac1ea846ec83ed1a
pdf-javascript-stream PDF /JS object 24 at offset 0x8D1 7341 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 4 long base64-like blob(s).