Malicious PDF — malware analysis report

Static analysis result for SHA-256 78427945d46e1c7e…

MALICIOUS

PDF

12.0 KB
MD5: 3e3f1058ef9013124a48227dbf1c2d27 SHA-1: 57529d2bb0ba64468ab0a67744d4d18430acac43 SHA-256: 78427945d46e1c7e2a643eb9f4087d1770e0eff5edd69e9c4cbff97422dc0789
76 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious File

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. ClamAV detection of Pdf.Exploit.Pdfka-9 further suggests exploitation of a known PDF vulnerability. The embedded JavaScript is the primary mechanism for delivering a malicious payload, likely a secondary stage downloader.

Heuristics 3

  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
a4c4c486706cf0c35b487989913cebe70ee9ac5fec5f219f6b6a9b69c5be40c6
pdf-javascript-stream PDF /JS object 76 at offset 0x369 11172 bytes
Detection
ClamAV: Pdf.Exploit.Pdfka-9
Obfuscation or payload: unlikely