Malicious PDF — malware analysis report

Static analysis result for SHA-256 af4ff84341b94a34…

MALICIOUS

PDF

45.3 KB
MD5: a9e33b6a025854de735b3b646a8f2410 SHA-1: 2d27dfb02387be738dc110e5ce1ec2d2f75a6dcd SHA-256: af4ff84341b94a34274a9440ce08f2bf7ca9fc3752e0ddf17ebbdc82321f6859
114 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/Scripting

The PDF contains embedded JavaScript, as indicated by multiple heuristic firings and the presence of a javascript_obj0012_000.js artifact. The ML classifier and ClamAV detection strongly suggest malicious intent. The embedded JavaScript is likely responsible for executing the malicious payload, although its specific actions are not detailed in the provided evidence. The document body is heavily obfuscated and does not provide clear user-facing content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9615

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
46fa6780dc597d5d049808f4814d5883ccfd3a9a919feab1e29b40181092a619
pdf-javascript-stream PDF /JS object 12 at offset 0xA1FC 3820 bytes