Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa2569cd86e8921f…

MALICIOUS

PDF

39.0 KB Created: Mu¼ÒLaVÎõ,wÈ:Xþþ,¨E‚û Authoring application: ÷°Ž¡}#f“Ä~G… ËÍ (via ÷°Ž²}#f™Ä{G„ ËÚ¤¼)
MD5: 4ea2c1b337b790f06c5bffe784468873 SHA-1: 1ab8c0f3b8323d4a3263e24e64c218b4ad7fb308 SHA-256: fa2569cd86e8921f0c2b62477e2e9ec7a299593c08b803e286e93c7a933411c0
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment

The PDF file is encrypted and contains embedded JavaScript, a common technique to obfuscate malicious content. The heuristic 'PDF_ENCRYPTED_WITH_JS' indicates that the JavaScript is used to hide the payload. While the specific intent of the JavaScript is not fully discernible due to obfuscation, its presence within an encrypted PDF strongly suggests a malicious purpose, likely for phishing or credential theft. No specific malware family could be identified.

Heuristics 4

  • Encrypted PDF carries /JavaScript — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/JavaScript). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0009_000.js
7416838d517e6b41f6da7fc4221e536618b827ad1645bff6d3ea34f2bbca82fe
pdf-javascript-stream PDF /JS object 9 at offset 0x3D6 37164 bytes