Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa7bd34d516f76cd…

MALICIOUS

PDF

37.3 KB Created: 2009-09-15 20:20:11 Authoring application: Scribus 1.3.3.13 (via Scribus PDF Library 1.3.3.13)
MD5: c3b8d4fc216476ee8c7210cb4ac97b33 SHA-1: 85a37c5fd6350d4710bbeda77d53b8a5ace0596c SHA-256: aa7bd34d516f76cd48990a281e4563d73e3a026579521b2296e6bf7ef89e05ba
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF was flagged by ML and ClamAV heuristics as malicious and obfuscated. It contains multiple embedded JavaScript streams, indicating it is designed to execute malicious code upon opening. The primary attack vector appears to be the exploitation of PDF vulnerabilities through JavaScript, likely to download and execute a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0017_000.js
d32d16e0503fc32b03085ea5442b01f937933d33bf10d9e6133810ab8c2624ca
pdf-javascript-stream PDF /JS object 17 at offset 0x4AE8 23948 bytes
javascript_obj0018_001.js
fe1be84dbc23222230db4d8727aa645c4d6a4c3d330c1d475bfa465bc3cfbc13
pdf-javascript-stream PDF /JS object 18 at offset 0x8D47 153 bytes
javascript_obj0019_002.js
9bdf2ce5d993bbc4cce31734218ce6e978854b79ac00df34f82f39421dd9baaa
pdf-javascript-stream PDF /JS object 19 at offset 0x8DFB 332 bytes
javascript_obj0020_003.js
c6533703157113c9a7c3dc8b8b49ff2a2344df931a6a7c343207028b647e15bd
pdf-javascript-stream PDF /JS object 20 at offset 0x8F37 156 bytes
javascript_obj0021_004.js
4a8824700078001a5ce3da9905003d6fbcd360e58a5c5b804af228c863a56b0b
pdf-javascript-stream PDF /JS object 21 at offset 0x9004 178 bytes