Malicious PDF — malware analysis report

Static analysis result for SHA-256 a29a369ded8e852c…

MALICIOUS

PDF

27.6 KB Created: GÓܚ컾4DMÆDÎaå%±ß 5 Authoring application: ýÖᯫ®‹â‚3ü* (via ýÖἫ®‹èƒ3ü=Îg)
MD5: d16476ce0998cbd659efe79a76b6e8fe SHA-1: ca4eba3be996f66f90dcf6d4ad062c32ad54e8e8 SHA-256: a29a369ded8e852cdc3fc7bbf84dd989b7d86231b73fa1aa3a885d13db1d7bdc
94 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript T1553.005 Subversion: Mark-of-the-Web Bypass

The PDF file is flagged as malicious by ML classifiers and contains embedded JavaScript, which is also encrypted. This suggests the JavaScript is used to obfuscate and deliver a malicious payload. The presence of PDF_ENCRYPTED_WITH_JS indicates that the PDF's content is hidden and likely executed via JavaScript, a common technique for downloading and running further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • Encrypted PDF carries /JavaScript — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/JavaScript). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0009_000.js
2fdb2d1ae47f5ee2d841adf6db7cc0a2e500207d4126eb4b507b575d3584eddf
pdf-javascript-stream PDF /JS object 9 at offset 0x3CB 25676 bytes