Malicious PDF — malware analysis report

Static analysis result for SHA-256 ecdc1720e4c1ef75…

MALICIOUS

PDF

7.7 KB Authoring application: Qimigiwova (via fffd2Bashemeriwesohitaro)
MD5: 3bf6587de6d3d2e3406f5d6ee43be214 SHA-1: d8a2d2c2dc37401930a6206145427d51bc904a08 SHA-256: ecdc1720e4c1ef75bf8746b932bef6fca22359ead6f8c802996661d384678884
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The ClamAV detection 'Heuristics.PDF.ObfuscatedNameObject' further suggests malicious obfuscation within the PDF structure. The embedded JavaScript stream, named 'javascript_obj0010_000.js', is the primary artifact and likely responsible for executing the malicious payload. The exact function of the script could not be fully determined due to potential obfuscation, but it is highly probable that it downloads and executes a second-stage payload.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0010_000.js
ed31b16df2b6492a4d5be85b534deca964c2f0e07a8443782787f4ed9c62c93c
pdf-javascript-stream PDF /JS object 10 at offset 0x1303 3192 bytes