Malicious PDF — malware analysis report

Static analysis result for SHA-256 ad11dd69e482c911…

MALICIOUS

PDF

77.2 KB Created: 2009-08-26 23:02:49 Authoring application: Scribus 1.3.3.13 (via Scribus PDF Library 1.3.3.13)
MD5: b02269b88efaf5b9eec62a3fd00987f4 SHA-1: 1f86d55ca4e28b7a4a4134ef36c33cc147ed48a6 SHA-256: ad11dd69e482c9110c2bba42b0de72e825c92a667c67c1e6b122bda302171cd8
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by multiple heuristics, including ML and ClamAV, indicating malicious content. Embedded JavaScript streams were detected, suggesting the file's primary function is to execute malicious code. The obfuscated nature of the JavaScript and the presence of multiple embedded streams point towards a downloader or dropper mechanism, likely intended to fetch and execute further malicious payloads from external sources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8846

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0087_000.js
eb85ac24e9caaae3a236e094302c36d6f9ebaaaddb2f4e43a26adef52782d29f
pdf-javascript-stream PDF /JS object 87 at offset 0xF22C 23524 bytes
javascript_obj0088_001.js
2a4788dfab87b00d554f3aed354f6b0296e9e1a0b1d8469b1a096d4245d84421
pdf-javascript-stream PDF /JS object 88 at offset 0x12863 208 bytes
javascript_obj0089_002.js
55dc3fb71aa74a0b783e682e8b6cdca17857445f8b044979909256b2eb2dcf75
pdf-javascript-stream PDF /JS object 89 at offset 0x12947 206 bytes
javascript_obj0090_003.js
767e7f67a0de9d802574dd77ac0cab346e941c73ea3e181d949af39441cf46c0
pdf-javascript-stream PDF /JS object 90 at offset 0x12A29 226 bytes