Malicious PDF — malware analysis report

Static analysis result for SHA-256 bb8de5e37bdd5c57…

MALICIOUS

PDF

45.5 KB
MD5: 189c2e0930f46ad83e9060e485974499 SHA-1: 8a2aec925bf6f6d7982d414c63e1a05a220afe41 SHA-256: bb8de5e37bdd5c57e4163fe4046b66a45e6d3e02097c91ddd0c88f00b338493e
116 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript T1553.005 Subvert Trust Controls: Mark-of-the-Web Bypass

The PDF was flagged by a machine learning classifier and ClamAV with 'Heuristics.PDF.ObfuscatedNameObject', indicating malicious intent. Embedded JavaScript streams and XFA form elements are present, suggesting the document is designed to execute code. The presence of these elements, combined with the ML and ClamAV detections, strongly points towards a malicious PDF designed to exploit vulnerabilities or deliver a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9615

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
4e06f3939202cd03d5b228cfa73e07b7ccb9dccc144b162a12d0088be8e87064
pdf-javascript-stream PDF /JS object 12 at offset 0xA1D9 4003 bytes