Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a3bf717b48b49ea…

MALICIOUS

PDF

6.7 KB
MD5: a5bf0a1aa94dbc10b753cb5969357237 SHA-1: 8a4c8ad27a58aa79200dc62bffb01e2e3aaab539 SHA-256: 8a3bf717b48b49eaf650b9210c5f11cd6a798829ef84716e74c145579d10c40c
66 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.002 Spearphishing Attachment

The PDF contains embedded JavaScript, flagged by heuristics as suspicious and malicious. The ML classifier strongly indicates maliciousness. The JavaScript appears to be obfuscated and likely attempts to redirect the user to the provided malicious URL, which is a common technique for phishing or malware delivery. The extracted JavaScript file name is also included as an IOC.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www2.safempwholder.de.lv/?o3z7y0=k5bnm7aV68aM2tbUtJ2lnJuL5uOft2eqYKjHmZ2mpLCaleDXoqOiZqprsmKplJ6L2eO0mqOdisbU0aW3ic17mdHPyaqjnduT

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0005_000.js
abbe2afdab69815bc9820ae60e50617ad1f696fcacd90fdc921d66b603809220
pdf-javascript-stream PDF /JS object 5 at offset 0x1D4 6067 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s). Carved artifact contains 1 long hex-escaped blob(s).