Malicious PDF — malware analysis report

Static analysis result for SHA-256 c5d884567d243fc6…

MALICIOUS

PDF

148.7 KB
MD5: 90890962d535f5bc55528bb352b914af SHA-1: 2f946b2d4c3dd4645a4ae2ca96c1e1c5883b97f5 SHA-256: c5d884567d243fc6788bcb7b6d629e4457d9b3c110b779c40e2a55b437419067
100 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1204.002 Malicious File: User Execution: Malicious PDF

The PDF file was detected as malicious by ClamAV with a critical heuristic for obfuscated objects. A high heuristic also indicated a launch action, suggesting an attempt to trigger an embedded exploit. The exact nature of the exploit or its payload could not be determined from the available evidence.

Heuristics 2

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • Launch action high PDF_LAUNCH
    PDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous