Malicious PDF — malware analysis report

Static analysis result for SHA-256 498d67250eac484d…

MALICIOUS

PDF

603.2 KB Created: ”¶ïB¬½þIóH}´;"Â6ºöhl«Ón…·ÏÅ7ñi1ªG/ ؔ7ÖX>ÄT Authoring application: }ã^Ý¿g4l–QZ½‹ð[H?Ã0¢âµÎÄ­µÍëФtw×ûßèfôc!°–òž (via KÂíªè;ÎañÚÓ´†e%Ò¿†NiV§²nø÷–\ä4lbÜ\Ôè3*Ün)
MD5: 6d05be2bdf34f3bf087981b717dc052e SHA-1: acc187771307e0936893ea4bdf6f4bf590d8d554 SHA-256: 498d67250eac484d5e7695fa9f02ef942cac91ad31200ba09bf14187d93fa0e8
276 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

This PDF file is identified as malicious due to the presence of embedded JavaScript and U3D content, which are indicators of exploitation. Specifically, the 'CVE_2011_2462' heuristic firing points to the exploitation of Adobe Reader's U3D and RichMedia parsers. The file also contains embedded files and is encrypted with JavaScript, further obscuring its malicious payload. ClamAV detection confirms its malicious nature as Pdf.Dropper.Agent-7212107-0.

Heuristics 11

  • Adobe Reader U3D/RichMedia parser exploit critical CVE likely CVE_2011_2462
    PDF combines U3D 3D content with RichMedia/Flash activation and JavaScript/action surfaces. This is the U3D RichMedia exploit document shape associated with CVE-2011-2462.
  • U3D/3D content in PDF — Adobe Reader 3D parser CVE-family indicator high CVE related PDF_U3D_CVE_RELATED
    PDF contains U3D (Universal 3D) or 3D annotation content — CVE-2011-2462 and CVE-2009-3953 are critical vulnerabilities in Adobe Reader's U3D processing that allow arbitrary code execution. U3D content in PDFs is extremely rare in normal documents.
  • ClamAV: Pdf.Dropper.Agent-7212107-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7212107-0
  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • Encrypted PDF carries /JavaScript — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/JavaScript). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 1 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser exited 1. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.