Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1500ef8dce105e4…

MALICIOUS

PDF

28.1 KB
MD5: 85cb6e2c05e4b430b6f692c15fbe5196 SHA-1: 05a4dbec93fbed62794f26c6aa7bc318a9d1ec34 SHA-256: f1500ef8dce105e48882b9ae138df6018ff8a19ef3d27e62f172f5fb8e17ea5f
66 Risk Score

Malware Insights

MITRE ATT&CK
T1559.002 Component Object Model Hijacking T1059.001 PowerShell

The PDF file contains embedded JavaScript and a Flash object (waEUHOXaQoR.swf). The JavaScript stream and the embedded Flash file are strong indicators of malicious intent, likely to exploit vulnerabilities or download further malicious content. The presence of these embedded objects suggests an attempt to bypass standard document security measures.

Heuristics 5

  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
waEUHOXaQoR.swf
767382813fc770c9716554c3266b22eee1636037ca964af05acf6ff66db4a27d
pdf-embedded-file PDF EmbeddedFile object 16 at offset 0x555 26993 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
javascript_obj0006_000.js
318a76e53bc4e4f9cdbe772df5af5ba43160b8bda75e64c4a9f561c1117fd7af
pdf-javascript-stream PDF /JS object 6 at offset 0xF9 265 bytes