Malicious PDF — malware analysis report

Static analysis result for SHA-256 f745a80b394ee9ef…

MALICIOUS

PDF

6.7 KB Created: 2010-09-01 09:19:50 Authoring application: Coqilzd (via 7c663Vezipovade)
MD5: d23526c7fe256cdc97b15d5820f1ac92 SHA-1: 01c19072a0ecf2f4a3fe6969fbba1d5edb47bfe2 SHA-256: f745a80b394ee9ef272010a4885f675e012dea5ab458aab73d52eb1252128ba5
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The ClamAV detection 'Heuristics.PDF.ObfuscatedNameObject' further suggests malicious intent through obfuscation. While the document body is unreadable, the presence of JavaScript actions strongly implies an attempt to execute code, likely to download and run a secondary payload. The SHA256 hash is included as a primary identifier.

Heuristics 3

  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0011_000.js
079179f2b5d2111982b6d25d3e16180f95f8876fd2c529b41f4158f5012771c5
pdf-javascript-stream PDF /JS object 11 at offset 0x121D 1942 bytes