Malicious PDF — malware analysis report

Static analysis result for SHA-256 6ab1485a4d0bdfc3…

MALICIOUS

PDF

202.6 KB Created: 2003-06-02 08:01:24 UTC Authoring application: Acrobat Web Capture 5.0
MD5: a16c76fac3b6a87013ab332a24a2568c SHA-1: b55a170ea48d6ff2255d82fec3ad460d5b650853 SHA-256: 6ab1485a4d0bdfc34c9addd64aa3356c6b2d475c660859b674af2cac97b1bb1e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment T1041 Exfiltration Over C2 Channel

The PDF contains embedded JavaScript that triggers a form submission to the URL http://www.royal-responder.com/rsp-cgi/respondpro/maxuseradmin.cgi. This action is indicative of a phishing attempt or data exfiltration, where user-submitted data is sent to a malicious server. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7871

Heuristics 8

  • PDF JavaScript submits form data to external URL high PDF_JS_SUBMITFORM_URL
    PDF JavaScript calls submitForm() with an external HTTP(S) URL. This can send form/document context to a remote endpoint or route the user into a credential-phishing flow. It is a behavioral indicator, not a parser exploit signal.
  • SubmitForm action medium PDF_SUBMITFORM
    PDF has a /SubmitForm action — form data can be silently posted to an attacker-controlled URL
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • External URI info PDF_URI
    PDF contains an external URL action
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.royal-responder.com/rsp-cgi/respondpro/maxuseradmin.cgi
    • http://www.royal-responde
    • http://store.yahoo.com/chesscafe
    • http://store.yahoo.com/chesscafe/1439.html
    • http://store.yahoo.com/chesscafe/ice165.html
    • http://store.yahoo.com/chesscafe/cb51.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/iX/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0094_000.js
20e407ccd789cb0132023d6da178ccdb397dafe1d32ece2b28f5676dad30b566
pdf-javascript-stream PDF /JS object 94 at offset 0x2D3FD 176 bytes
stream_013_off00010db0.bin
2e883c97a37b5c7db6d2c1efc7acfced439d7f172d00b60721c00090cd9fcbcf
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x10DB0 4032 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 15 long base64-like blob(s).
stream_014_off00011485.bin
378f1f6e0cdc9208fd2ea61c41903a20ee37a30da6dc6497de7a0bb1ebb32fc7
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x11485 19966 bytes
stream_016_off0001864f.bin
5c5ca5d6c268284a81de3c178f15e786d14bb87c3208042a04348d2db5127172
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1864F 60192 bytes