PDF static analysis report

Static analysis result for SHA-256 5f93a056721aa3d2…

SUSPICIOUS

PDF

143.0 KB First seen: 2019-05-16
MD5: 6f558ee17a5cf48a21cc088acbe8f4ef SHA-1: 5bb60f4c9847d21979f4a1e51fd55de205779575 SHA-256: 5f93a056721aa3d2af855534a5f87931d0e000e0a2f2c8246b9efbe88802dfa8
56 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains embedded JavaScript, identified by the PDF_JAVASCRIPT and PDF_JS heuristics, which is likely responsible for downloading and executing a second-stage payload. The document body presents a fake course drop form to trick the user into interacting with the malicious content. The embedded file and script payload heuristics further support the conclusion that this PDF is designed to deliver malware.

Machine Learning

  • Nyx PDF Classifier clean score 0.0207

Heuristics 7

  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ocsp.verisign.com0 In extracted file (font_00_sfnt_off00000d8d.bin)
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xfa/promoted-desc/In PDF document text
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://ns.adobe.com/xdp/In extracted file (embedded_file_obj0001.bin)
    • http://www.xfa.org/schema/xci/2.6/In extracted file (embedded_file_obj0002.bin)
    • http://www.xfa.org/schema/xfa-template/2.6/In extracted file (embedded_file_obj0003.bin)
    • http://www.w3.org/1999/xhtmlIn extracted file (embedded_file_obj0003.bin)
    • http://www.xfa.org/schema/xfa-data/1.0/In extracted file (embedded_file_obj0003.bin)
    • http://www.xfa.org/schema/xfa-template/2.8/In extracted file (embedded_file_obj0003.bin)
    • http://www.xfa.org/schema/xfa-locale-set/2.6/In extracted file (embedded_file_obj0004.bin)
    • http://ns.adobe.com/xfdf/In extracted file (embedded_file_obj0007.bin)
    • http://www.xfa.org/schema/xfa-form/2.8/In extracted file (embedded_file_obj0008.bin)
    • http://crl.verisign.com/tss-ca.crl0In extracted file (font_00_sfnt_off00000d8d.bin)
    • http://crl.verisign.com/ThawteTimestampingCA.crl0In extracted file (font_00_sfnt_off00000d8d.bin)
    • https://www.verisign.com/rpaIn extracted file (font_00_sfnt_off00000d8d.bin)
    • http://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0DIn extracted file (font_00_sfnt_off00000d8d.bin)
    • https://www.verisign.com/rpa0In extracted file (font_00_sfnt_off00000d8d.bin)
    • http://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0In extracted file (font_00_sfnt_off00000d8d.bin)
    • http://www.adobe.com/typehttp://www.adobe.com/type/legal.htmlIn extracted file (font_00_sfnt_off00000d8d.bin)

Extracted artifacts 15

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0001.bin pdf-embedded-file PDF EmbeddedFile object 1 at offset 0x1F61D 163 bytes
SHA-256: bca11f45dec9a0b78db00f591689c9a2c1451f5916075275870ba56e74fe6c27
embedded_file_obj0002.bin pdf-embedded-file PDF EmbeddedFile object 2 at offset 0x1F70D 1678 bytes
SHA-256: f58005d521c4f52662f4ebde969ea759f403f6f10a502f621abd91bc3f7365e0
embedded_file_obj0003.bin pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x1FA24 50263 bytes
SHA-256: 1ad802ec881efb9c2a6037db9b68f6c27a1344327df56ae76041da14d4f969bf
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
embedded_file_obj0004.bin pdf-embedded-file PDF EmbeddedFile object 4 at offset 0x219A0 2860 bytes
SHA-256: bfff1586053f8005ff03b85b76471914c8ed164445b816ae476d50b551f1e7c8
embedded_file_obj0005.bin pdf-embedded-file PDF EmbeddedFile object 5 at offset 0x21CF6 642 bytes
SHA-256: 55aba32b75c834cf60f6fdc6f08ff7cef02b198141ec7ddbae95cc92dd77d87d
embedded_file_obj0006.bin pdf-embedded-file PDF EmbeddedFile object 6 at offset 0x21DF0 1535 bytes
SHA-256: 796387548f51426d8ebcc4001c5456e153f122c66bae5c3833bc3e9d2ddc04d2
embedded_file_obj0007.bin pdf-embedded-file PDF EmbeddedFile object 7 at offset 0x220B2 80 bytes
SHA-256: 2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19
embedded_file_obj0008.bin pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x2215B 56 bytes
SHA-256: 4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1
stream_002_off0000044f.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x44F 1313 bytes
SHA-256: f94e41f586bf3f20bc1deeac4bfbda388a61db43f25fbd6304ba73f5653368cf
stream_003_off0000062e.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x62E 902 bytes
SHA-256: 1b2ec98752b966f601d5223a750559cf13d562ac5e5c6d1fcc7217835b01f5fd
objstm_0158_00.bin pdf-objstm-decoded PDF /ObjStm 158 0 obj (inflated) 17597 bytes
SHA-256: 035ef35c93953fe01813a424aa9470ebb9b719e904cb35b9e970f80c944e6453
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 6 long base64-like blob(s).
font_00_sfnt_off00000d8d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD8D 94351 bytes
SHA-256: 1626e6329f65d0d35cdf751ec668ac4b8800d726707d01e7810bb8297d789dee
font_01_sfnt_off00014905.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14905 18729 bytes
SHA-256: 60392219c979657a154ac2351a42b69592872719c343f0371f4804dfe69905e3
font_02_sfnt_off00017903.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x17903 26921 bytes
SHA-256: 46baf82d5aedadb59af4c72516485d12b05a5664d7af4d6cc1c8608c4747c07e
font_03_sfnt_off0001c1db.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1C1DB 17842 bytes
SHA-256: 32818e9755179b592ffdbef3119a84ae818977587fdef86586d0b4adfb423ecc