Malicious PDF — malware analysis report

Static analysis result for SHA-256 7412a03300c5471d…

MALICIOUS

PDF

343.9 KB Created: 2011-06-30 15:13:40 +08:00 Authoring application: Writer (via OpenOffice.org 3.0) First seen: 2012-09-15
MD5: b74be46373b56fb7ef23705bca8e1000 SHA-1: d9401fb79b51bd4884a3fa1a7674f857ee209530 SHA-256: 7412a03300c5471d1c4791f3a8720b4cea6a0a407547d243041d2357a5839e53
306 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 JavaScript

The PDF contains embedded JavaScript and RichMedia (Flash) content, with critical findings indicating exploitation of CVE-2011-0611. The embedded JavaScript stream contains a URL that, while benign according to reputation, is suspicious in this context. The presence of embedded files and the ML classifier's high score further support a malicious classification. The primary attack vector appears to be exploiting a Flash vulnerability to achieve code execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9109

Heuristics 11

  • Adobe Flash Player RichMedia exploit critical CVE likely CVE_2011_0611_FLASH_RICHMEDIA
    PDF combines RichMedia Flash activation with an embedded AS3 SWF loader (ByteArray/loadBytes) and shellcode heap-spray staging. This is the static exploit shape associated with CVE-2011-0611 Flash content delivered through Adobe Reader.
  • Embedded PDF child has suspicious static findings critical PDF_EMBEDDED_CHILD_STATIC_TRIAGE
    PDF contains an embedded PDF stream whose extracted child matches suspicious or malicious PDF heuristics. Wrapper PDFs are commonly used to hide the actual exploit or lure payload from scanners that do not recursively inspect attachments.
  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector (matched inside decoded stream)
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 37 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic (matched inside decoded stream)
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.monotype.comhttp://www.monotype.com/html/type/license.html In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://ns.adobe.com/xdp/In PDF document text
    • http://www.xfa.org/schema/xci/2.8/In PDF document text
    • http://www.xfa.org/schema/xfa-template/2.8/In PDF document text
    • http://www.xfa.org/schema/xfa-data/1.0/In PDF document text
    • http://www.xfa.org/schema/xfa-locale-set/2.7/In PDF document text
    • http://ns.adobe.com/xtd/In PDF document text
    • http://www.xfa.org/schema/xfa-form/2.8/In PDF document text
    • http://www.monotype.com/html/mtname/ms_timesnewroman.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlNOTIFICATIONIn PDF document text

Extracted artifacts 24

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0001.bin pdf-embedded-file PDF EmbeddedFile object 1 at offset 0x380F 163 bytes
SHA-256: 2bbe69c5e9b01e09ead01d39980623115955d79663f86ee38c3e26d62468aede
embedded_file_obj0002.bin pdf-embedded-file PDF EmbeddedFile object 2 at offset 0x38FF 1683 bytes
SHA-256: 2db2fcfa6c7f0b58af35cd0b7a546eab3e22594fa9e6a322d8448248c1371742
embedded_file_obj0003.bin pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x3C21 784 bytes
SHA-256: 6824595d40fe37ff3a17665623abb424df29f2bf3924106e83b1192a2fc6fa0d
embedded_file_obj0004.bin pdf-embedded-file PDF EmbeddedFile object 4 at offset 0x3E15 150 bytes
SHA-256: 720c47f19e6a058099295d18a16b7149cc73fe497eb78821ea810f3192228dc4
embedded_file_obj0005.bin pdf-embedded-file PDF EmbeddedFile object 5 at offset 0x3EE6 2955 bytes
SHA-256: c8a82f67dfd8d68c2f8fe494ca2deee4604701c8f02863bf87d222b992e45de9
embedded_file_obj0006.bin pdf-embedded-file PDF EmbeddedFile object 6 at offset 0x4260 200 bytes
SHA-256: 4cb349134bdb5f1a1c03281df9b53128ebe947f235398a912a4f0a9f638b24d5
embedded_file_obj0007.bin pdf-embedded-file PDF EmbeddedFile object 7 at offset 0x4353 835 bytes
SHA-256: 41b90835819d2fc9adfbed1f624b97daf557be436627d29ad24fdfcbedc74198
embedded_file_obj0008.bin pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x452B 56 bytes
SHA-256: 4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1
embedded_file_obj0072.bin pdf-embedded-file PDF EmbeddedFile object 72 at offset 0x7E20 162 bytes
SHA-256: 676abdf89259991bbde6a57a2423c629870a437bc477a903574eba3570861622
embedded_file_obj0073.bin pdf-embedded-file PDF EmbeddedFile object 73 at offset 0x7F10 96 bytes
SHA-256: b646c863068dd809ba1fe5481aecb499465f1bd3a044f7733fe3d3935e312efb
javascript_obj0075_000.js pdf-javascript-stream PDF /JS object 75 at offset 0x7FF5 44 bytes
SHA-256: b4c77449deb96f0bd59c15743f54f9192b3b7e5a2f49d6a129eb783aa7e7d78f
Preview script
First 1,000 lines of the extracted script
app.alert("                              ");
stream_002_off000003d6.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3D6 1363 bytes
SHA-256: 529357503ec67b623d2a12816cdeea62bd639f2b4ff4e568b01c96cc3f5bfc6f
stream_003_off000005b3.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5B3 902 bytes
SHA-256: e985b5df65c8c3cf732a9074b575fbc594c1c7f0bccc0994182ec7e5c0f7308a
objstm_0041_00.bin pdf-objstm-decoded PDF /ObjStm 41 0 obj (inflated) 1575 bytes
SHA-256: cc0d110077f81314ac59a491675430d25faa86bdc2526ed35971cf361ac83464
stream_006_off000088d4.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x88D4 38286 bytes
SHA-256: ded940b77b9a3e0e4eaa9475cad5e9eb88e987a0b7ab9f46cb752799f3aca6c4
objstm_0016_00.bin pdf-objstm-decoded PDF /ObjStm 16 0 obj (inflated) 967 bytes
SHA-256: 3cbf19b006091b3e421e5c1cd1c8127430c1fddb99de414cc59098dfd09ec272
font_00_sfnt_off0002fccf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2FCCF 37416 bytes
SHA-256: cfd8475624654acefe85dfed82dabe01906f123e364aa1043e26d7815b7265f5
font_01_sfnt_off00033317.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x33317 20984 bytes
SHA-256: 8e07373218a8cecb46c7c5566504c7080ce21bc372ce6f368f14bdb4510a7003
font_02_sfnt_off00035afd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x35AFD 106496 bytes
SHA-256: 0541cde01f28c81f0d9bb6e95d678a1e01068b9a37e3c8fca61e58bd2aa3c0f8
font_03_sfnt_off000447d8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x447D8 101444 bytes
SHA-256: b34a020970be6e4fbf81919a74322ca3be17673735317d3eb44ac1dbf365d36b
polyglot_child_pdf_off00022a21.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x22A21 210330 bytes
SHA-256: b77e993fee155b257f8557009504642db418d645b3e28c1e1c7c2b744787278b
polyglot_child_pdf_off0002e93e.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x2E93E 161405 bytes
SHA-256: e97c41e2d40cfbfde01c6c7e519f237a38379767a2c34e174db6834c4e4a55ef
polyglot_child_pdf_off00052fe1.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x52FE1 12250 bytes
SHA-256: 8819803854b223925788808ea24ee7a401ca69f44e88d076d044728a12bf3180
polyglot_child_pdf_off000547ce.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x547CE 6125 bytes
SHA-256: 0b1c923c8a0028794f3a3244dc498786746334f394e41678cc58ffbeb707d0a8