Malicious PDF — malware analysis report

Static analysis result for SHA-256 90d24b2df7ce564f…

MALICIOUS

PDF

8.3 KB
MD5: 38e6677270f6c0092f58ed047c0eb9d1 SHA-1: ddb97ca2e46a3383b1191bd6acf96e464754997d SHA-256: 90d24b2df7ce564f4194f6b10693fa563bf06275703a91c85705d827b9751634
76 Risk Score

Malware Insights

The PDF contains embedded JavaScript, indicated by multiple heuristic firings related to PDF JavaScript actions and streams. ClamAV also flagged the file due to obfuscated objects, suggesting malicious intent. The presence of JavaScript points towards an attempt to execute arbitrary code, likely to download and run a secondary payload.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.