Malicious PDF — malware analysis report

Static analysis result for SHA-256 4641fff6f4d06843…

MALICIOUS

PDF

320.0 KB Created: 2008-01-05 16:25:50 +01:00 Authoring application: LaTeX with hyperref package (via pdfeTeX-1.21a)
MD5: 63b5293121d5da996034164025b99b37 SHA-1: 4331e696faa0f808fd4f02829dfc12573117adaa SHA-256: 4641fff6f4d068434b5304c80bb2a600f04138e0e853435d40681befa331dcd1
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious Link

The PDF file contains embedded JavaScript and U3D content, which is flagged as a CVE-related indicator. The embedded JavaScript is likely responsible for exploiting a vulnerability, potentially related to the U3D content, to execute malicious code. The document also contains external URIs that could be used for further payload delivery or command and control. The presence of JavaScript actions and embedded JS streams strongly suggests an attempt to leverage these for malicious purposes.

Heuristics 7

  • U3D/3D content in PDF — Adobe Reader 3D parser CVE-family indicator high CVE related PDF_U3D_CVE_RELATED
    PDF contains U3D (Universal 3D) or 3D annotation content — CVE-2011-2462 and CVE-2009-3953 are critical vulnerabilities in Adobe Reader's U3D processing that allow arbitrary code execution. U3D content in PDFs is extremely rare in normal documents.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser exited 1. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://vcg.isti.cnr.it)/S/URI/Type/Action
    • http://meshlab.sourceforge.net)/S/URI/Type/Action
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/pdfx/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://vcg.isti.cnr.it
    • http://meshlab.sourceforge.net

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0015_000.js
1f14163b18a0dd9c1620895d8541a53dd197273f7999faee5066fadc473eb3bd
pdf-javascript-stream PDF /JS object 15 at offset 0x665 5452 bytes
stream_006_off00024ab2.bin
b1f937b9541d599e1c6000c4c47f7f3f21a4d9b0e1051c8a5580e07bc6106afd
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x24AB2 177792 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.72, consistent with packed or encrypted content.
font_00_type1_off00021e57.bin
f1d06dc0327817e03d778a88f65436557134c269106fbc5438dd4ef0c897a441
pdf-font-stream PDF embedded font (type1) at offset 0x21E57 11287 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.76, consistent with packed or encrypted content.