Malicious PDF — malware analysis report

Static analysis result for SHA-256 2542e62399811511…

MALICIOUS

PDF

16.9 KB
MD5: 2332ad5a20d86edb8c840d1b21793dec SHA-1: b0244be4d808090e393a17ec6e3a1260dbe855d4 SHA-256: 2542e62399811511af04fd7c507c18e2ee275569c15234c111e158deef6714c4
118 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.001 Malicious Link

The PDF sample contains obfuscated JavaScript, including multiple eval() calls and string concatenations, indicating an attempt to hide malicious code. The critical heuristic firing for CVE-2009-4324 confirms the exploit mechanism. The deobfuscated JavaScript suggests the primary goal is to download and execute a secondary payload, likely from a remote source, which is a common technique for initial access and further system compromise.

Heuristics 5

  • media.newPlayer — CVE-2009-4324 critical CVE exact CVE_2009_4324
    PDF JavaScript calls media.newPlayer — CVE-2009-4324 is a use-after-free in Adobe Reader's multimedia plugin triggered by media.newPlayer(). Actively exploited as a zero-day in December 2009. (identified after JavaScript deobfuscation)
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj111711_000.js
8b08e662c595bc05798a33ba7f54e31f86b1652e9082a1c86320bbfb549984f1
pdf-javascript-stream PDF /JS object 111711 at offset 0x18E 2998 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 6 long base64-like blob(s).
javascript_obj111712_001.js
8d15b28fa19818576c0e4da6849594cec22fb67f972c41c2ba18182e31b20bed
pdf-javascript-stream PDF /JS object 111712 at offset 0xD7A 11473 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 6 long base64-like blob(s).
javascript_obj111713_002.js
ef374e3c14b5a0ef68032d8ad61db14b185e68efa03834a023ffc7bbac6dcde4
pdf-javascript-stream PDF /JS object 111713 at offset 0x3A81 2258 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 5 long base64-like blob(s).
legacy_pdfkit_stage_000.js
3af672dfcc1afa5bf58c9f0f873abaa25352c06c31913820aee3811b939271af
deobfuscated-js multi-marker percent-array decoded JavaScript at offset 0xD7A 1074 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s).
legacy_pdfkit_stage_001.js
67032520672104e686bc10583b57b8f00ee6cde9748dc8350b76e9c6009cbfb3
deobfuscated-js multi-marker percent-array decoded JavaScript at offset 0x3A81 171 bytes
legacy_pdfkit_stage_002.js
a5bd2564f305bad34ecd6855d8815faca3ca3db887a8fec13e98e3dfd5b09828
deobfuscated-js multi-marker percent-array combined decoded JavaScript at offset 0xD7A 1246 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s).