Malicious PDF / .SWA — malware analysis report

Static analysis result for SHA-256 d43159647c18dd98…

MALICIOUS

PDF / .SWA

7.2 KB Authoring application: Bofatezozinefaxfa (via 67ab2Vogewojixariuawi)
MD5: 30e768fba1cb14dc8fbd458445a4561b SHA-1: 8636d7bcb2048726fa93b1cbbf0d9fd24791fca7 SHA-256: d43159647c18dd98ab940ef5cf1577a342ae964a470499f1709d52a0329d0f33
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript

The PDF file contains embedded JavaScript, indicated by heuristic firings for PDF_JAVASCRIPT and PDF_JS. The ClamAV detection of 'Heuristics.PDF.ObfuscatedNameObject' further suggests malicious intent. The embedded JavaScript is likely responsible for exploiting a vulnerability within the PDF reader to execute arbitrary code, although the specific payload or action is not discernible from the provided evidence. The document body is heavily obfuscated and does not provide clear textual lures.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
ca838ab153ea9de4fff1e74bdd0848fd720f71bc6fbee4425be234136cd19b41
pdf-javascript-stream PDF /JS object 11 at offset 0x1349 2325 bytes