Malicious PDF — malware analysis report

Static analysis result for SHA-256 de97802e9e2c531e…

MALICIOUS

PDF

34.4 KB
MD5: a19506773bcc9ae658e8478c9ef4bfbd SHA-1: 064765772d369509a5ee90066c38daef28cc1d08 SHA-256: de97802e9e2c531ef7577df7231d0757cfe54d11788483f16e1c13ffd18b5125
76 Risk Score

Malware Insights

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings related to PDF and JavaScript. ClamAV also flagged the file as malicious due to obfuscated objects. The embedded JavaScript is likely responsible for executing a malicious payload, although the specific actions are not detailed in the provided evidence.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.