Malicious PDF — malware analysis report

Static analysis result for SHA-256 9515916ac23c826a…

MALICIOUS

PDF

45.9 KB
MD5: 5b821d437a022970e1444d8a6401a9f3 SHA-1: d8f69d054b6454d4831fcad6c251d162d0e6b40e SHA-256: 9515916ac23c826a319f49d6fec5501b2fe354d2f01abce9ec27740e002786e1
84 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The ClamAV detection Heuristics.PDF.ObfuscatedNameObject further suggests malicious obfuscation within the PDF structure. While the document body is unreadable, the presence of obfuscated JavaScript points to an attempt to execute malicious code, likely for downloading further payloads or exploiting vulnerabilities. The specific intent of the JavaScript could not be fully determined due to obfuscation.

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
e51d795ac1d613abaf77e5d95c4cd1d5b5964b09efaed4af0979393ff8c1e721
pdf-javascript-stream PDF /JS object 12 at offset 0xA1F0 4232 bytes