Malicious PDF — malware analysis report

Static analysis result for SHA-256 b270a37b7780e00e…

MALICIOUS

PDF

6.7 KB Created: 2010-09-01 09:19:50 Authoring application: Coqilzd (via b8b23Vezipovade)
MD5: a92b1b998bb5239136b0ab8cd2899619 SHA-1: 62a86dea0976eb4d99bebd3e6cc73351e54aa19a SHA-256: b270a37b7780e00e6001dae3ef2148fdd251156f8afb5faaf50ff3b6b06aa335
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF containing obfuscated JavaScript, as indicated by the PDF_JAVASCRIPT and PDF_JS heuristics, and ClamAV detection. The embedded JavaScript is likely responsible for exploiting a vulnerability within the PDF reader to execute malicious code. The exact nature of the payload is not discernible from the provided evidence, but the presence of JavaScript actions strongly suggests an attempt to download and execute a secondary stage. The authoring application 'Coqilzd' and the creation date are also noted.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
079179f2b5d2111982b6d25d3e16180f95f8876fd2c529b41f4158f5012771c5
pdf-javascript-stream PDF /JS object 11 at offset 0x121D 1942 bytes