Malicious PDF — malware analysis report

Static analysis result for SHA-256 f19a872e31732a2c…

MALICIOUS

PDF

45.6 KB
MD5: 5837dc76e454735a6fd6b66cfa01c7e0 SHA-1: 28657850b316c89a847d6e5797748822a1ef529a SHA-256: f19a872e31732a2c14d6d71b698876f178faa20c4518c504a4ddb851e7d3aa48
84 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file exhibits characteristics of malicious intent, including the presence of embedded JavaScript and XFA form elements, which are often used for obfuscation and exploitation. ClamAV detected this file as Heuristics.PDF.ObfuscatedNameObject, indicating a high likelihood of malicious activity. The embedded JavaScript, though not fully analyzed due to potential obfuscation, is a common vector for delivering second-stage payloads or exploiting known vulnerabilities within PDF readers.

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
7637af3c6d179d88cf70a7971112379317aec36b287682fdfddc4c746f4ade59
pdf-javascript-stream PDF /JS object 12 at offset 0xA1D5 3958 bytes