Malicious PDF — malware analysis report

Static analysis result for SHA-256 2c3e1ea1d0c551cc…

MALICIOUS

PDF

1.4 KB
MD5: 1e9155d9384ab58581ab93eda8b08662 SHA-1: f1d4854208587efac9380c32a6b59754ee5cbca1 SHA-256: 2c3e1ea1d0c551ccb7030922fff72410dc78114c26266f511b7bcd290ecd9037
118 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious File T1059.007 Command and Scripting Interpreter: JavaScript

The PDF file contains embedded JavaScript, which is obfuscated and utilizes the unescape function. A critical heuristic identified the CVE-2009-4324 vulnerability related to the media.newPlayer object, indicating the script is likely intended to exploit this flaw. The script's purpose is to download and execute a second-stage payload, although the exact URL is not directly visible due to obfuscation.

Heuristics 5

  • media.newPlayer — CVE-2009-4324 critical CVE exact CVE_2009_4324
    PDF JavaScript calls media.newPlayer — CVE-2009-4324 is a use-after-free in Adobe Reader's multimedia plugin triggered by media.newPlayer(). Actively exploited as a zero-day in December 2009. (matched in decompressed stream)
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj111111_000.js
9d810005232d035f0c5142ca2264c6d76add87070c8c1dfb4650905d2e761448
pdf-javascript-stream PDF /JS object 111111 at offset 0x160 1265 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
javascript_obj111112_001.js
d910a14b7fa3a29f2e31ae684cfe59729cc1ce48aea93e570f3d6f3ec92bf945
pdf-javascript-stream PDF /JS object 111112 at offset 0x48C 244 bytes