Malicious PDF — malware analysis report

Static analysis result for SHA-256 85589f7e05b1ee5b…

MALICIOUS

PDF

5.9 KB
MD5: 74c36b5c80c854f864ccdbb435ece956 SHA-1: f7e95d7f57dac54282d3871d00732f4f0bd37510 SHA-256: 85589f7e05b1ee5bc5c13a27fbe2b1b6ce3effa18a164c5fb78facd21dd4d39e
76 Risk Score

Malware Insights

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings. This JavaScript is likely used to exploit vulnerabilities within the PDF reader or to download and execute a secondary payload. The ClamAV detection of 'Heuristics.PDF.ObfuscatedNameObject' further supports the malicious nature of the file, suggesting attempts to hide malicious content.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.