Malicious PDF — malware analysis report

Static analysis result for SHA-256 83fdbf356e3d0de0…

MALICIOUS

PDF

45.7 KB
MD5: 45d091bbbde850bc2cf6c824a15a31ae SHA-1: a08e5d3f00a0653684d5fdf8fb0c8119d6ad4c94 SHA-256: 83fdbf356e3d0de024b5ca4ab71a83365578b5964b57ab62bf1effb438e65dbd
84 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript T1566.001 Phishing: Spearphishing Attachment

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The ClamAV detection of 'Heuristics.PDF.ObfuscatedNameObject' further suggests malicious intent through obfuscation. While the document body is unreadable, the presence of JavaScript points towards an attack pattern involving script execution, potentially for downloading further malware or exploiting a vulnerability. The embedded URLs are related to XFA forms, which can sometimes be used in PDF exploits.

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
f01ff177ed58c6fe153ea8db1dc7e682f267b37c95536298c8b94ba199236fe1
pdf-javascript-stream PDF /JS object 12 at offset 0xA1F3 4167 bytes