Malicious PDF — malware analysis report

Static analysis result for SHA-256 4145cd9b78191920…

MALICIOUS

PDF

45.8 KB
MD5: 17be5f925da2d8be329f82bc914dfe1a SHA-1: 97343663bc697cf96e7fe6dfa447b87ea6938637 SHA-256: 4145cd9b781919206e5049e1a78c0ac68ce1a4226de3957795ac704407e2838b
98 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File Execution: Malicious JavaScript T1027 Obfuscated Files or Information

The PDF file contains embedded JavaScript that utilizes the Collab.getIcon method, indicative of the CVE-2009-0927 vulnerability in Adobe Reader. The JavaScript is obfuscated and decodes multiple layers to ultimately execute an exploit stage. This suggests the file is designed to compromise the user's system by leveraging this known vulnerability.

Heuristics 5

  • Collab.getIcon — CVE-2009-0927 critical CVE exact CVE_2009_0927
    PDF JavaScript calls Collab.getIcon — CVE-2009-0927 is a stack buffer overflow in Adobe Reader triggered by Collab.getIcon() with a crafted argument. Allows arbitrary code execution. (identified after JavaScript deobfuscation)
  • ASCIIHexDecode filter (with exploit indicators) medium PDF_FILTER_HEX
    Hex-encoding filter present alongside exploit delivery indicators — often used to hide payload or shellcode bytes
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
df20e6c4bd3de6362e99ca2f09d4172ea23b6e0019c16f5e07aaa48948febdc1
pdf-javascript-stream PDF /JS object 8 at offset 0x1D3 9215 bytes
custom_b64_stage_000.js
eaf25136d1ad5ccacaeac7f1aee20634165859e38aef26a6d23452bbd7a1fdfd
deobfuscated-js custom Base64 decoded JavaScript layer 2 (PDF /JS object 8) at offset 0x8A7 1517 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s).