MALICIOUS
214
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1566.002 Spearphishing Attachment
The PDF contains embedded JavaScript, which is a common technique for delivering malicious payloads. Static analysis identified a secondary embedded PDF with suspicious findings, including JavaScript and obfuscation. The ClamAV detection 'Heuristics.PDF.ObfuscatedNameObject' further indicates malicious intent. The primary attack pattern involves luring the user to open the PDF, which then triggers the execution of the embedded JavaScript, leading to the loading of the secondary malicious PDF.
Heuristics 8
-
Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGEA valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
-
ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTIONClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
-
ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAVClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
-
Optional Content Group with action trigger low PDF_OPTIONAL_CONTENTOptional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0004_000.jsbe7f5eaa31879a245b9c8a3d48e82cd2cdec4706a9c7b40e9f418d4a1872c7f3 |
pdf-javascript-stream | PDF /JS object 4 at offset 0x75 | 10763 bytes |
javascript_obj0014_001.jsb53ac129acfd382e4ae6a4c51f238b86e1d60e6b741a99651705fffcaca1ef03 |
pdf-javascript-stream | PDF /JS object 14 at offset 0x1A0C | 111 bytes |
polyglot_child_pdf_off000071b9.pdff87cdb8b88e0c34b1c6acb32c17676613e47cbfc7f0983275ab77239af4e9241 |
polyglot-child-pdf | Secondary PDF body inside pdf container at offset 0x71B9 | 2018887 bytes |
|
Detection
ClamAV:
Heuristics.PDF.ObfuscatedNameObject
Obfuscation or payload:
likely
Carved artifact contains 1 long base64-like blob(s).
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.