Malicious PDF — malware analysis report

Static analysis result for SHA-256 67b0345403439f78…

MALICIOUS

PDF

106.4 KB Created: 2018-06-12 09:41:10 -04:00
MD5: 0cc8237a69e7f031c6bc0c2a91e1c792 SHA-1: f03dea36a1bfd4f70f159193e2630975da439ebd SHA-256: 67b0345403439f783c3a04fc8b1c7a1ac8c559dcb1783b533ae4829f7a466ace
160 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains JavaScript that triggers an alert mimicking an Adobe Acrobat update prompt. This script also attempts to submit form data to a suspicious URL, indicating a phishing or credential harvesting attempt. The embedded JavaScript is designed to lure the user into clicking a link that likely leads to the download of a second-stage malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9477

Heuristics 8

  • PDF auto-runs JavaScript form submission on open critical PDF_OPENACTION_JS_SUBMITFORM
    PDF uses /OpenAction to run JavaScript that calls submitForm() with an external HTTP(S) URL. Opening the document triggers the outbound submission path without requiring a normal link click.
  • PDF JavaScript shows fake Acrobat updater prompt high PDF_FAKE_ACROBAT_UPDATE_LURE
    PDF JavaScript displays Acrobat/update-themed language such as a document rendering engine update or remote connection to Adobe servers. When paired with JavaScript or external submission, this is a social-engineering lure rather than benign document text.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://testing.user-click.phishtrain.org/XYWNx0aW9uPWuF0dGFjaGa1lbnyQmzcmVjmaXBpZW50uX2llkPTQ2NjA2MTMwJmNhebXBhaWduX3J1bl9pZD0yMTE4NDk=#FDF
    • http://testing.user-click.phishtrain.org/XYWNr0aW9uPWpNsaWNrJnnVybDz1ovdHRwaczovL3NlkY3lVyZS5lbmNyeXB0ZWRjgb25uZWN0aW9uLm5ldC9wYWdlcy9jMzk1NWIxYzQ4YSZyZWNpcGllbnRfaWQ9NDY2MDYxMzAmY2FtcGFpZ25fcnVuX2lkPTIxMTg0OQ==
    • http://testing.user-click.phishtrain.org/XYWNk0aW9uPWqNsaWNrJntVybDp1ondHRwsczovL3NlwY3jVyZS5lbmNyeXB0ZWRjeb25uZWN0aW9uLm5ldC9wYWdlcy9jMzk1NWIxYzQ4YSZyZWNpcGllbnRfaWQ9NDY2MDYxMzAmY2FtcGFpZ25fcnVuX2lkPTIxMTg0OQ==
    • http://testing.user-click.phishtrain.org/XYWNs0aW9uPWoNsaWNrJnjVybDe1ovdHRweczovL3NlpY3mVyZS5lbmNyeXB0ZWRjzb25uZWN0aW9uLm5ldC9wYWdlcy9jMzk1NWIxYzQ4YSZyZWNpcGllbnRfaWQ9NDY2MDYxMzAmY2FtcGFpZ25fcnVuX2lkPTIxMTg0OQ==
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/exif/1.0/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
66823e8731f5035573cb7fcb88ca766215256ccd64d060f70805b231ae8d96c1
pdf-javascript-stream PDF /JS object 12 at offset 0x180A 393 bytes
javascript_obj0012_001.js
60f7a06e0104c5040918e84df74b46791115b08fbbcc5c4d7dc0bfa95676c1f0
pdf-javascript-stream PDF /JS object 12 at offset 0x1831 102786 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 7 long base64-like blob(s).
font_00_cff_off000192a7.bin
9340d372ad75a105fdb1627a30e96f892e0dc7d9588c0150cf06b4fa72281cc0
pdf-font-stream PDF embedded font (cff) at offset 0x192A7 4575 bytes