Malicious PDF — malware analysis report

Static analysis result for SHA-256 467eafa931cd633e…

MALICIOUS

PDF

2.7 KB
MD5: 4159b54873f9aae8b4db31766b3bf262 SHA-1: fb089c41eb4798ddb601828bd58460fa4845c95c SHA-256: 467eafa931cd633e1e7ef6eec32e2f7cfbe6f7b53ce219dbff9a737ee6d2cfc2
72 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript and RichMedia (Flash) content, indicated by heuristic firings. The presence of 'test.swf' in the document body suggests an attempt to load or execute external Flash content, likely to exploit a vulnerability. The embedded JavaScript stream is the primary mechanism for initiating this exploit, aiming to compromise the user's system.

Heuristics 6

  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0006_000.js
b07c0be26608a2c3510aa71eca85f9b33b5c7f43f1fa432fe92d9131491207c2
pdf-javascript-stream PDF /JS object 6 at offset 0x106 1573 bytes