Malicious PDF — malware analysis report

Static analysis result for SHA-256 b88ec97190ea8be7…

MALICIOUS

PDF

34.1 KB
MD5: 07f9304c3471eacdff4f92cae55d9be4 SHA-1: 2a80d850365e871399aecad28fa1f837acfe770d SHA-256: b88ec97190ea8be731784f7db5a2b8d0e77bb771a8586ac513ea707b2634a477
76 Risk Score

Malware Insights

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings related to PDF and JavaScript. ClamAV also flagged the file as malicious due to obfuscated objects. The presence of JavaScript suggests an attempt to execute malicious code, likely to download and run a secondary payload.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.