Malicious PDF — malware analysis report

Static analysis result for SHA-256 acfc879400015623…

MALICIOUS

PDF

34.9 KB Created: ©…½ÕI‚"‡@Íbðÿ‰WðPä3}ví Authoring application: @¦xV²·ü!Á¤» (via @µxV²u·ü Á¨»Û)
MD5: 172de574bb88c4920ff8ce60b3b6fc91 SHA-1: 8c85b6c2ad1a3172aa85824d2a0953c27c9fc138 SHA-256: acfc8794000156238de1166a74e5923b46f7aa19d53916e64e223b77cf56a3df
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file is encrypted and contains embedded JavaScript, a common technique to hide malicious content from static analysis. The heuristic 'PDF_ENCRYPTED_WITH_JS' indicates that the JavaScript is used to obfuscate the payload. The large embedded JavaScript object suggests it is responsible for the malicious functionality, likely downloading and executing a second-stage payload. The SHA256 hash is included as a primary identifier.

Heuristics 4

  • Encrypted PDF carries /JavaScript — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/JavaScript). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0009_000.js
45865f065a880bbebfa273b46a7e0f05e027a4f580ac5db07efd0b5a227d0f24
pdf-javascript-stream PDF /JS object 9 at offset 0x3BC 33074 bytes