Malicious PDF — malware analysis report

Static analysis result for SHA-256 737050a50d2bccd6…

MALICIOUS

PDF

107.5 KB Created: 2018-06-12 09:41:10 -04:00
MD5: e3eb011d07ccb70cfa5f3bd2a9516a1c SHA-1: c8c279d6f67f2612b0ace541ad4bc04a15db8490 SHA-256: 737050a50d2bccd63524a0d0dbf0a635d2c7aa1ee7cb23a1650bac4efbaa65f6
200 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains JavaScript that automatically triggers an alert message mimicking an Adobe Acrobat update prompt. It then attempts to submit form data to a suspicious URL, likely to download a secondary payload or phish for credentials. The presence of JavaScript and the fake update lure strongly indicate a malicious intent to exploit user trust.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9477

Heuristics 9

  • PDF auto-runs JavaScript form submission on open critical PDF_OPENACTION_JS_SUBMITFORM
    PDF uses /OpenAction to run JavaScript that calls submitForm() with an external HTTP(S) URL. Opening the document triggers the outbound submission path without requiring a normal link click.
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • PDF JavaScript shows fake Acrobat updater prompt high PDF_FAKE_ACROBAT_UPDATE_LURE
    PDF JavaScript displays Acrobat/update-themed language such as a document rendering engine update or remote connection to Adobe servers. When paired with JavaScript or external submission, this is a social-engineering lure rather than benign document text.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nam05.safelinks.protection.outlook.com.url.ATP-redirect.protected-forms.com/XWkRSTGNYRk9iaXRQZWpGR00xUkZkbVZNZW5SNVEwazJjVzEwTVRndmJYSk9lVmRZVGt4VVZrY3dNR1ZwWnpkb1Z5OUdlRGs1YkVOeldFdGpNWGwxU25jcmFsaHJZVVIyTDA1TVEzWnNWekJZT1ZSSFpqbHFkM1ZoUTI1NmNXNHhSVFJuVlhSRGNVUTRaa0U5TFMwd1RuTklaekY1TUhGcWNEQnNWSGcwUTFWc1FraEJQVDA9LS03OGZiMDhkNGNiMWZhMjk1ZmZkYzEzNDk5ZDg0Y2EwNDk4MmExNjU2?cid=902955127#FDF
    • https://nam05.safelinks.protection.outlook.com.url.ATP-redirect.protected-forms.com/XUmpaUU1rMU5jVk5tU0N0M1dVOUNNSE41WVRab1FqbEVNVXhOVWtSTWQzQnVhbHBZVjNGcWFVRjJNQ3MxZGtreFNWaFBPRzlJTXpGTVdVRnNhSFUyWm5kSVNHdG9PVUpDZW0wNFdXbFJaRFJOYmtScU1tSnRTWEJFVUdRemVGVTFjalJCV0hkcU5qaFZMM1F2V1Zac2MyRnVVVWxpUzFaU2VrRnRXR3hRV1ZWNmQyUmxkazlOV1VRNWNtUnZNQ3RDY1dsVGRXMVlNRGRDTW1GVmRFRXhaRXh1WkVGWlNERTJlblJKUFMwdFoxYzJNRWMzZUcxNGFGRkNPUzh2Y3psMFpFeElaejA5LS0xMWY2M2UyOGNhYzM0Njk0MzBmYjliOGQ4YjUxYmQ1YmYzNWYwOGJi?cid=902955127
    • https://nam05.safelinks.protection.outlook.com.url.ATP-redirect.protected-forms.com/XTjJnMVpWRXJSRUUzYzJ4NVpIRkthSEl2Ym5sTFZHTnZSMjR5VlRCa1VGTm9WbXBVTjJnMWJWSjJZa3N2YXpKb2EyUnVUU3Q2VURReUsxSnVLMVJsTjNsdVdFTkhiMlZVUkhJdk1GbFNNakpuZVVkWE5rMDNlbGQ0YlhndmQwTTVla0ZCU0hSYU0wNWxTRmxNUjBGMmRYUk1jWE12TkROVVRFWmpMMHRuVXpKRFZtVkVkM1U1Wms5QmVIbFVUSGhtZDBOUFZWSTBObWxZT1ZrM2EyRXdkbVE1ZDBSTmNXMTFSRGRKUFMwdFJFSklWRFU0VldRMGRYSlRUVGRQTjNObmJEQmhVVDA5LS00YzE2YWRiMGYyOThmZmFhOWJkZGI0MzMxODcwYjc2Njk3NDY1MWVj?cid=902955127
    • https://nam05.safelinks.protection.outlook.com.url.ATP-redirect.protected-forms.com/XT1ZwQlN6QndjbE15UjBwT2FXVmtkVzVRVUZGR1RuQm9OVXMxYW5OQ2NETlJNRmQyU0VKRUx6aElabFpVWjJNdmJGY3lkMlZNTms1VGFraFBhVXc1VUZwMlNVSTFhblJ4ZVZwa1RHb3dWbU5SVTJKMGRsb3JSV3hMYUhWSVNIcEhTako1YWtFMmVub3pVMkpJY0hFMWVXeElMMG81ZFhZeVVDODBkRGhOZGt4WE5YSXJhRnBDY1hNNWVsYzFNMVl6VnlzNFNIWm1XbGRsWWtSUk5Ha3JNWE5RVVc1dVRXMWthbG80UFMwdEt6a3ZXVXRIYWtwNU9UQk5SVUpoUm10WVpFczFRVDA5LS03N2ZiMWU1ZjU1YjY2MTEzYmVhYjQyZTVhYmU2ZTBmN2RlZjA1NDkx?cid=902955127
    • https://nam05.safelinks.protection.outlook.com.url.ATP-redirect.protected-forms.com/XUmpaUU1rMU5jVk5tU0N0M1dVOUNNSE41WVRab1FqbEVNVXhOVWtSTWQzQnVhbHBZVjNGcWFVRjJNQ3MxZGtreFNWaFBPRzlJTXpGTVdVRnNhSFUyWm5kSVNHdG9PVUpDZW0wNFdXbFJaRFJOYmtScU1tSnRTWEJFVUdRemVGVTFjalJCV0hkcU5qaFZMM1F2V1Zac2MyRnVVVWxpUzFaU2V
    • https://nam05.safelinks.protection.outlook.com.url.ATP-redirect.protected-forms.com/XUmpaUU1rMU5jVk5tU0N0M1dVOUNNSE41WVRab1FqbEVNVXhOVWtSTWQzQnVhbHBZVjNGcWFVRjJNQ3MxZGtreFNWaFBPRzlJTXpGTVdVRnNhSFUyWm5kSVNHdG9PVUpDZW0wNFdXbFJaRFJOYmtScU1tSnRTWEJFVUdRemVGVTFjalJCV0hkcU5qaFZMM1F2V1Zac2MyRnVVVWxpUzFaU2VrRnRXR3hRV1ZWNmQyUmxkazlOV1VRNWNtUnZNQ3RDY1dsVGRXMVlNRGRDTW1GVmRFRXhaRXh1WkVGWlNERTJlblJKUFMwdFoxYzJNRWMzZUcxNGFGRkNPUzh2Y3psMFpFeElaejA5LS0xMWY2M2UyOGNhYzM0Njk0MzBmYjliOGQ4YjUxYmQ1YmYzNWYwOGJi?cid=90
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/exif/1.0/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
ca46085b3ed8fbd1ec023b8a518a11705ac15b31219cb07b5e6cbf8033f7f11b
pdf-javascript-stream PDF /JS object 12 at offset 0x180A 653 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
javascript_obj0012_001.js
f915b52b16379a2fb6cebf06937bfc663cac88ad1df98d0f7ef7336a52a26d1d
pdf-javascript-stream PDF /JS object 12 at offset 0x1831 103934 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 8 long base64-like blob(s).
font_00_cff_off00019723.bin
9340d372ad75a105fdb1627a30e96f892e0dc7d9588c0150cf06b4fa72281cc0
pdf-font-stream PDF embedded font (cff) at offset 0x19723 4575 bytes