Malicious PDF — malware analysis report

Static analysis result for SHA-256 8145f97c22ffce3c…

MALICIOUS

PDF

45.0 KB
MD5: 1984601b2d5f1280dae32490afabc2d4 SHA-1: 85bb8c542992f3a24580d3297924162863dcbb7a SHA-256: 8145f97c22ffce3cf86294befadb563f040452f1659a57bfbed993c94ee48185
84 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file exhibits characteristics of malicious intent, including the presence of embedded JavaScript and XFA form elements, which are often used to obfuscate malicious code or exploit vulnerabilities. ClamAV detected this file as Heuristics.PDF.ObfuscatedNameObject, indicating a known pattern of malicious PDF activity. The embedded JavaScript, though not fully analyzed due to obfuscation, is a common vector for delivering second-stage payloads. The extracted URLs, while some are benign, are associated with the document's structure and could potentially be leveraged in a broader attack chain.

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
3c8b12b8403afd5521547e6fe93814691c8eacbd9e0e3051eaeba78e64288a00
pdf-javascript-stream PDF /JS object 12 at offset 0xA1EB 3421 bytes