Malicious PDF — malware analysis report

Static analysis result for SHA-256 df6df406ec859e71…

MALICIOUS

PDF

45.4 KB
MD5: 4c5b211a82816868e324dd6fa4d62f00 SHA-1: 83f7d0284f7ffa61a5f9956ba6b1897c8f4674cb SHA-256: df6df406ec859e7115165008ea6afe05824eff8ba73e33ed821e9239fb790f1a
84 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file exhibits characteristics of malicious intent, including embedded JavaScript and XFA form elements, which are often used to deliver exploits or malware. ClamAV flagged it as Heuristics.PDF.ObfuscatedNameObject, indicating a deliberate attempt to obscure its contents. The embedded JavaScript, though obfuscated, is a common vector for further compromise. The presence of XFA suggests a potential for complex document interactions that could be leveraged maliciously.

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
97e8789187b36a4c4d3bbe3b4365e5c86b3815db3d8899ee4d17872bdb7cc432
pdf-javascript-stream PDF /JS object 12 at offset 0xA1FA 3843 bytes