Malicious PDF — malware analysis report

Static analysis result for SHA-256 f32668b4aed1568a…

MALICIOUS

PDF

45.2 KB
MD5: a9cca69176c59673406ab53fdb97c927 SHA-1: 5089e66dd236b7c7dc1a885ca680893dc0600f99 SHA-256: f32668b4aed1568a735217f4946f08567cac517d6ccdcea1caa0482e284ae6c0
84 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains embedded JavaScript, indicated by the 'PDF_JAVASCRIPT' and 'PDF_JS' heuristics. The 'CLAMAV_DETECTION' heuristic with 'Heuristics.PDF.ObfuscatedNameObject' further suggests malicious intent due to obfuscation. While the document body is unreadable, the presence of JavaScript points towards an attempt to execute code, likely for downloading and executing a second-stage payload. The specific JavaScript content could not be fully analyzed due to obfuscation, leading to a moderate confidence score.

Heuristics 5

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
7dc9c507ef428bfb8cb35c92a94420733b6cd1b2a9f3610bdb5fab544ead2eb3
pdf-javascript-stream PDF /JS object 12 at offset 0xA1EB 3606 bytes