Malicious PDF — malware analysis report

Static analysis result for SHA-256 7df1f7902f6cda1b…

MALICIOUS

PDF

7.2 KB Authoring application: Bofatezozinefaxfa (via 88b1eVogewojixariuawi)
MD5: 31fb47ca8b4e8df3bc5d7e2bfa38fda4 SHA-1: 7bc6869752cba441891cc8ab7a7c7963042795e5 SHA-256: 7df1f7902f6cda1b6f65f5ea774b433dee44a9c7db33c92c32298f914ebfd14b
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file was detected as malicious by ClamAV due to obfuscated JavaScript content. The embedded JavaScript stream is indicative of an attempt to execute arbitrary code upon opening the PDF. This behavior aligns with common techniques for delivering second-stage payloads, such as downloading and running additional malware. The file's SHA256 hash is provided as a primary indicator.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
ca838ab153ea9de4fff1e74bdd0848fd720f71bc6fbee4425be234136cd19b41
pdf-javascript-stream PDF /JS object 11 at offset 0x1349 2325 bytes