Malicious PDF / .SWA — malware analysis report

Static analysis result for SHA-256 a131d8a5c78638c7…

MALICIOUS

PDF / .SWA

6.6 KB Created: 2010-09-03 08:30:58 Authoring application: Wigejobawaqivlirore (via c0a23Loxidakeneveb)
MD5: ed66f5f0f52ccd29f004cdc716bc233d SHA-1: 0e6bdad88045e10730c28c118abd2656621be2f3 SHA-256: a131d8a5c78638c723899f2c9b0546da362b7b78c6d23ef7aaf83a807f4d8c55
146 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains embedded JavaScript, flagged by multiple heuristics as obfuscated and malicious. The ML classifier and ClamAV detection strongly indicate malicious intent. The JavaScript action and embedded JS stream suggest the document is designed to execute arbitrary code, likely to download and run a second-stage payload. The authoring application and creation date are also suspicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • Page-word XOR JavaScript eval stager high PDF_PAGE_WORD_XOR_EVAL_STAGER
    PDF JavaScript enumerates rendered page words with getPageNthWord/getPageNumWords, extracts encoded byte fragments, XOR-decodes the stage with char-code helpers, and evals the result. This is an old exploit-kit staging pattern and is not normal document JavaScript.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0010_000.js
f41461c6d0ad7c5b3366f5afcb8bd0df9b874c9b0f5ff46847255e6ad0726ba1
pdf-javascript-stream PDF /JS object 10 at offset 0x11A1 1999 bytes