Malicious PDF — malware analysis report

Static analysis result for SHA-256 92eca85b30cf3c79…

MALICIOUS

PDF

6.2 KB
MD5: 2ae2dd05b76d1a8995078273e0e7c89f SHA-1: fbc4feca45a53772796c81d32b5a7d11427ca95f SHA-256: 92eca85b30cf3c792f81ed5bacf4a85fdad6b3eb67a982d0dcc0af4e765fb5c6
126 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1559.002 Component Object Model Hijacking

The PDF file exhibits multiple indicators of malicious activity, including embedded JavaScript and RichMedia (Flash) content. The ClamAV detection for 'Heuristics.PDF.ObfuscatedNameObject' and the presence of a suspicious JavaScript file ('javascript_obj0006_000.js') strongly suggest an attempt to execute malicious code. The embedded RichMedia artifact, identified as 'vPoYDxnrxjd.swf', further supports the likelihood of exploit delivery or payload execution. The exact intent of the embedded scripts could not be fully determined due to obfuscation, but the overall structure points towards a malicious exploit or downloader.

Heuristics 6

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0006_000.js
d86ea334f271309352c9f5f79f0cd77d79accaf91aca3540eaaac362bd9be64b
pdf-javascript-stream PDF /JS object 6 at offset 0x144 4177 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).