Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba362fa46ba7be02…

MALICIOUS

PDF

3.7 KB
MD5: 9098567130004665ea236b683f1c5760 SHA-1: cbf8af625a0f8ee3b3c6cb545d68065513df55d1 SHA-256: ba362fa46ba7be023492eab4888a88bb583a04d5542f267fb696cd671487a5ae
76 Risk Score

Malware Insights

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings related to PDF and JavaScript. ClamAV also flagged it as malicious due to obfuscated objects. The embedded JavaScript is likely used to exploit vulnerabilities or download further malicious content, a common technique for PDF-based malware delivery.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.