Malicious PDF — malware analysis report

Static analysis result for SHA-256 f662bb9c9048ed0d…

MALICIOUS

PDF

27.8 KB Created: òx•ƒ@B˶D,~=P,ÿŸº°§ Authoring application: CHȔoó§dµ¥_(/¡$ÛÉV|ᣠ(via Rxىdâ§qߨ@0f>¶%’Ÿl çÆ—”áNþa)
MD5: 0b3726c378179f0b42f37176042c917f SHA-1: 0638089ad306daa0f9b8fd6c25ddb5822a0c5b6c SHA-256: f662bb9c9048ed0da4c0343a290ef59b283cd94151011752e2802af0b355b3a6
124 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1027 Obfuscated Files or Information

The critical ClamAV detection of 'Eicar-Test-Signature' strongly indicates malicious intent. The PDF is encrypted and contains embedded JavaScript, a common technique to conceal malicious code from static analysis and deliver a second-stage payload. The presence of JavaScript actions and embedded JS streams further supports this. While the exact payload is hidden, the overall pattern suggests an attempt to exploit vulnerabilities or trick the user into executing malicious code.

Heuristics 5

  • ClamAV: Eicar-Test-Signature critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Eicar-Test-Signature
  • Encrypted PDF carries /JavaScript — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/JavaScript). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0013_000.js
91b4e2bcc1ff86cd3fd9d5e3a1db856b7a434c348e231cb552b8d79b32d2bff4
pdf-javascript-stream PDF /JS object 13 at offset 0x12E2 1438 bytes