Malicious PDF — malware analysis report

Static analysis result for SHA-256 719e2f8c62b8d03a…

MALICIOUS

PDF

275.4 KB Created: 2018-08-24 17:51:07 +01:00 Authoring application: Microsoft® Word 2016
MD5: afb73072a58ad463c08247159f45ec2c SHA-1: df6c2e9abed2e414184d3d2fe05dfe4e54b0bc09 SHA-256: 719e2f8c62b8d03a5503f4d523b9da0dece973b2afd8f2b4c32690c7ae7916f7
74 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF document that impersonates a cloud document lure, aiming to trick users into clicking malicious links. It contains a heuristic indicating it is related to CVE-2023-26369 and uses XFA forms, suggesting exploitation of PDF vulnerabilities. The embedded URLs point to suspicious domains, likely serving as the initial stage for a multi-stage attack.

Machine Learning

  • Nyx PDF Classifier clean score 0.0243

Heuristics 6

  • TrueType bitmap font + active content — CVE-2023-26369 related high CVE related PDF_CVE_2023_26369_RELATED
    PDF embeds a TrueType font with bitmap tables (EBDT/sbix/CBDT) alongside exploit delivery indicators — CVE-2023-26369 exploits the sfac_GetSbitBitmap function in Adobe's libCoolType for arbitrary code execution. This CVE was actively exploited in the wild, but this rule does not validate the malformed EBLC/EBDT primitive.
  • Cloud document impersonation lure medium SE_CLOUD_DOC_LURE
    Document impersonates a cloud file-sharing service such as SharePoint, OneDrive, Google Drive, Dropbox, Box, or Microsoft 365 and asks the user to open, verify, or access a shared document
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://conchislandphotography.com/.%40.%40.%40.%40/.%40.%40.%40.%40?%7blink%7d&kjhgdhj=%7bdomain%7d&sdfg=iuyu
    • https://earthholding.com/jhdjhdjhd/
    • https://maderamundial.com/*@_@@@@@@@@@@/*@@@@@@@_@@@@@@@
    • http://www.w3.org/1999/xhtml
    • http://www.xfa.org/schema/xfa-data/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.aiim.org/pdfa/ns/extension/
    • http://www.aiim.org/pdfa/ns/property#
    • http://www.aiim.org/pdfa/ns/schema#
    • http://www.aiim.org/pdfa/ns/id/
    • http://www.microsoft.com/typography/ctfontshttp://lucasfonts.comMicrosoft
    • http://en.wikipedia.org/wiki/MIT_License
    • http://www.microsoft.com/typography/fonts/default.aspx
    • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0X
    • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
    • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
    • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0
    • http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
    • http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
    • http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^
    • http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��
    • http://www.microsoft.com/pkiops/docs/primarycps.htm0@
    • http://www.microsoft.com/Typography
    • http://www.iec.ch

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0001cdc1.bin
6ab6d176503e3398d59a98d998d70a97f18813a6a0f4e34d1eb4cd1576aebf08
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1CDC1 115244 bytes
stream_005_off0002755c.bin
706c99981821fc3e23150c8e689bcd6b88718515d8065081f8fab144b4786eb3
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2755C 101888 bytes
icc_00_off000389a8.icc
f02b2ee205805857ca2466141f69defb7f00c29e3ab1ee6695893df0aa65d7b1
pdf-icc-profile PDF ICC profile at offset 0x389A8 3920 bytes
icc_04_off0003eee2.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x3EEE2 3144 bytes