Malicious PDF — malware analysis report

Static analysis result for SHA-256 783b7c1a2cadbc8b…

MALICIOUS

PDF

69.5 KB
MD5: 6b050df970c4d910a122b4e0e9276184 SHA-1: a37bdfa65d1abea2275bed1a5481d602448f9031 SHA-256: 783b7c1a2cadbc8b3016d3524804429ba4486128e452f6ee2fefbee407255879
132 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The PDF sample was flagged by multiple heuristics, including ML classification and ClamAV, for obfuscated object names and general maliciousness. The embedded URL, while not explicitly used in the provided document body excerpt, suggests a potential command and control or payload delivery vector. The ML classifier's high score indicates a strong likelihood of malicious intent, likely involving exploitation of a client-side vulnerability.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9876

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • Hex-obfuscated structural name object high PDF_OBFUSCATED_NAME_OBJECT
    A structurally-dangerous PDF name (e.g. /OpenAction, /Launch, /AA, /EmbeddedFile, /SubmitForm) is written with #XX hex escapes to evade string-based scanners. Legitimate producers write these names literally; hex-encoding them is a deliberate obfuscation technique.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.bitstream.com