MALICIOUS
80
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains embedded JavaScript and leverages a U3D/3D content vulnerability (CVE-family indicator) in Adobe Reader. The embedded JavaScript is likely used to download and execute a second-stage payload. Several external URIs were extracted, with http://www.cacetech.com/ being the most frequently referenced and having an unknown reputation.
Machine Learning
- Nyx PDF Classifier clean score 0.0670
Heuristics 6
-
U3D/3D content in PDF — Adobe Reader 3D parser CVE-family indicator high PDF_U3D_CVE_RELATEDPDF contains U3D (Universal 3D) or 3D annotation content — CVE-2011-2462 and CVE-2009-3953 are critical vulnerabilities in Adobe Reader's U3D processing that allow arbitrary code execution. U3D content in PDFs is extremely rare in normal documents.
-
ASCIIHexDecode filter (with exploit indicators) medium PDF_FILTER_HEXHex-encoding filter present alongside exploit delivery indicators — often used to hide payload or shellcode bytes
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.cacetech.com/ PDF link annotation
- http://www.wi-fiplanet.com/tutorials/article.php/1447501In PDF document text
- http://netbsd.gw.com/cgi-bin/man-cgi?ieee80211_radiotap+9+NetBSD-currentIn PDF document text
- http://www.cacetech.com/support/downloads.htmIn PDF document text
- http://www.aircrack-ng.org/In PDF document text
- http://www.oxid.it/cain.htmlIn PDF document text
- http://www.wiresharku.com/In PDF document text
- http://www.winpcap.org/devel.htmIn PDF document text
- http://www.winpcap.org/contact.htmIn PDF document text
- http://www.cacetech.comPDF link annotation
- http://www.wiresharku.comIn PDF document text
- http://www.cacetech.com/)/TypeIn PDF document text
- http://www.wi-fiplanet.com/tutorials/article.php/1447501)/TypeIn PDF document text
- http://netbsd.gw.com/cgi-bin/man-cgi?ieee80211_radiotap+9+NetBSD-current)/TypeIn PDF document text
- http://www.cacetech.com/support/downloads.htm)/TypeIn PDF document text
- http://www.aircrack-ng.org/)/TypeIn PDF document text
- http://www.oxid.it/cain.html)/TypeIn PDF document text
- http://www.wiresharku.com/)/TypeIn PDF document text
- http://www.winpcap.org/devel.htm)/TypeIn PDF document text
- http://www.winpcap.org/contact.htm)/TypeIn PDF document text
- http://www.monotype.comMonotypeReferenced by PDF JavaScript
- http://ocsp.verisign.com0Referenced by PDF JavaScript
- http://www.monotype.comHowardReferenced by PDF JavaScript
- http://standards.ieee.org/getieee802/802.11.htmlIn PDF document text
- http://technet2.microsoft.com/WindowsServer/en/library/370b019f-711f-4d5a-8b1e-4289db0bcafd1033.mspx?mfr=trueIn PDF document text
- http://www.wireshark.org/tools/wpa-psk.htmlIn PDF document text
- http://www.wireshark.org/docs/In PDF document text
- http://wiki.wireshark.org/In PDF document text
- http://www.wireshark.org/lists/In PDF document text
- http://technet2.microsoft.com/WindowsServer/en/library/370b019f-711f-In PDF document text
- http://standards.ieee.org/getieee802/802.11.html)/TypeIn PDF document text
- http://technet2.microsoft.com/WindowsServer/en/library/370b019f-711f-4d5a-8b1e-4289db0bcafd1033.mspx?mfr=true)/TypeIn PDF document text
- http://www.wireshark.org/tools/wpa-psk.html)/TypeIn PDF document text
- http://www.wireshark.org/docs/)/TypeIn PDF document text
- http://wiki.wireshark.org/)/TypeIn PDF document text
- http://www.wireshark.org/lists/)/TypeIn PDF document text
- http://www.monotype.com/html/mtname/ms_arial.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlReferenced by PDF JavaScript
- https://www.verisign.com/rpaReferenced by PDF JavaScript
- http://ocsp.verisign.com/ocsp/status0Referenced by PDF JavaScript
- https://www.verisign.com/rpa0Referenced by PDF JavaScript
- http://crl.microsoft.com/pki/crl/products/CodeSignPCA.crl0Referenced by PDF JavaScript
- http://www.microsoft.com/typographyReferenced by PDF JavaScript
- http://www.monotype.com/html/mtname/ms_timesnewroman.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlReferenced by PDF JavaScript
- http://crl.verisign.com/ThawteTimestampingCA.crl0Referenced by PDF JavaScript
- http://crl.verisign.com/tss-ca.crl0Referenced by PDF JavaScript
- http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0OReferenced by PDF JavaScript
- http://www.microsoft.com/pki/certs/CodeSignPCA2.crt0Referenced by PDF JavaScript
- http://www.monotype.com/html/mtname/ms_couriernew.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlReferenced by PDF JavaScript
- https://www.verisign.com/repository/RPA0Referenced by PDF JavaScript
- https://www.verisign.com/repository/CPSReferenced by PDF JavaScript
+4 more URL(s)
Extracted artifacts 6
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0279_000.js |
pdf-javascript-stream | PDF /JS object 279 at offset 0xA80CF | 58 bytes |
SHA-256: 53ef3e86395c29047481d41061937b32759780f8b45be9739a0a576f50df45b1 |
|||
Preview scriptFirst 1,000 lines of the extracted script
this.print({bUI:true, bSilent:false, bShrinkToFit:false});
|
|||
font_00_sfnt_off000095e2.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x95E2 | 84640 bytes |
SHA-256: 3728a5aebee02754b48cc7c833a7dfd2c1643eeea58671c2b05dd4425a81e80b |
|||
font_01_sfnt_off0000ea7e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEA7E | 36196 bytes |
SHA-256: 50a8af41ddd97b9d5e20669845738f9de1de6267192fe2c17eb152c0ecd1443e |
|||
font_02_sfnt_off0001d41d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1D41D | 95036 bytes |
SHA-256: 6ba9731d6c154e83c45b54a57d6756e51f08bbe979d986c1dfc6d9a68c93e319 |
|||
font_03_sfnt_off0002e95a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2E95A | 116728 bytes |
SHA-256: 5ee6023599431d8a3bf65ba2502e507a9f4930f2b79d6c892d94812be7e501fa |
|||
u3d_00_off000a7f23.bin |
pdf-3d-stream | PDF U3D 3D stream at offset 0xA7F23 | 292 bytes |
SHA-256: bd2530871157199c20c44d2549da670059332e38e61c5ce3e612b2cf973bed1d |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.