Malicious PDF — malware analysis report

Static analysis result for SHA-256 0bdbafcb4b8cee59…

MALICIOUS

PDF

146.2 KB
MD5: e83fdfb03c1d2e2a146b483718a34a51 SHA-1: a5e144c3ef2e65cbd8be93797ecd5137b81340d9 SHA-256: 0bdbafcb4b8cee59e0422b2da4fa17d1cda5fd4c162fd1ab5f7df1acd60d395d
106 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 JavaScript

The PDF contains embedded JavaScript that leverages CVE-2009-4324 by calling the media.newPlayer API. This exploit is designed to execute arbitrary code, and the deobfuscated script confirms the use of this technique. The primary goal appears to be downloading and executing a secondary payload, as indicated by the script's structure and the critical heuristic firing.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • media.newPlayer — CVE-2009-4324 critical CVE exact CVE_2009_4324
    PDF JavaScript calls media.newPlayer — CVE-2009-4324 is a use-after-free in Adobe Reader's multimedia plugin triggered by media.newPlayer(). Actively exploited as a zero-day in December 2009. (identified after JavaScript deobfuscation)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
5844deecad338e6ac4753fded09089488924557becc7a359308b41e39d8d8822
pdf-javascript-stream PDF /JS object 8 at offset 0x210 3125 bytes
legacy_pdfkit_stage_000.js
42c3f4df375ff6f58ff655cc4f88b5cc28f0dd33b978390db3538684a6219b74
deobfuscated-js string-concatenation normalized Acrobat API aliases at offset 0x210 126 bytes