Malicious PDF — malware analysis report

Static analysis result for SHA-256 11d19e27f38218db…

MALICIOUS

PDF

861 B
MD5: dfad2cba3bfc3f458242587edeb37b1d SHA-1: 3bbe199813dd122c0960c3fcbdf981b63cc564fc SHA-256: 11d19e27f38218db1d25f830e85ae60e7fbf550d9d64af71fca376187828dfbf
106 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 JavaScript

The PDF file contains embedded JavaScript that attempts to exploit the CVE-2009-4324 vulnerability via the media.newPlayer function. This exploit allows for arbitrary code execution within the context of the PDF viewer. The ML classifier strongly indicates maliciousness, and the critical heuristic confirms the use of a known exploit.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • media.newPlayer — CVE-2009-4324 critical CVE exact CVE_2009_4324
    PDF JavaScript calls media.newPlayer — CVE-2009-4324 is a use-after-free in Adobe Reader's multimedia plugin triggered by media.newPlayer(). Actively exploited as a zero-day in December 2009.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0005_000.js
ae57568eb4406e1b810bbbae8fc8ca79307260ad045cecfa8c89056cddb0856a
pdf-javascript-stream PDF /JS object 5 at offset 0x117 333 bytes
combined_document_js_000.js
aa13c479a1890b4031b63c4bcae5ccb2d83c11e882d6a05482575d8c99811dd4
deobfuscated-js combined document JavaScript streams at offset 0x117 358 bytes