Malicious PDF — malware analysis report

Static analysis result for SHA-256 75f041e39bee2c00…

MALICIOUS

PDF

553.5 KB Created: 2010-03-31 12:55:11 -04:00 Authoring application: Adobe InDesign CS4 (6.0.4) (via Adobe PDF Library 9.0)
MD5: bc725ed906ba976de8290359317f9cdc SHA-1: 6507c9f7ce6e6abc2140066826cf77ea26726f38 SHA-256: 75f041e39bee2c007740caac6fa6a3e8014964d90f41bbca382bcc89df91ca99
100 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.002 Malicious Link: Malicious File T1059 Command and Scripting Interpreter T1059.001 Command and Scripting Interpreter: PowerShell T1105 Ingress Tool Transfer

The PDF contains embedded files and a remote GoTo action, indicating an attempt to redirect the user or download additional content. The ML classifier strongly suggests malicious intent. The embedded artifacts and heuristic firings point towards a downloader or exploit delivery mechanism, likely aiming to fetch and execute a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8662

Heuristics 4

  • Embedded PDF child has suspicious static findings critical PDF_EMBEDDED_CHILD_STATIC_TRIAGE
    PDF contains an embedded PDF stream whose extracted child matches suspicious or malicious PDF heuristics. Wrapper PDFs are commonly used to hide the actual exploit or lure payload from scanners that do not recursively inspect attachments.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Remote GoTo action info PDF_GOTO_REMOTE
    PDF has GoToR/GoToE actions that reference sibling document files — typical of multi-part document bundles
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/g/img/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/xap/1.0/sType/ManifestItem#
    • http://ns.adobe.com/xmp/InDesign/private
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/t/pg/
    • http://ns.adobe.com/xap/1.0/sType/Dimensions#
    • http://ns.adobe.com/xap/1.0/g/

Extracted artifacts 9

Files carved from inside the sample during analysis.

FilenameKindSourceSize
andromeda_neptune_673.pdf
83d7416f7c7301f238f4e0272d83c3af25788b013c351a2ce5ba910043b79eb3
pdf-embedded-file PDF EmbeddedFile object 244 at offset 0x1A9FA 224371 bytes
andromeda_neptune_673_1.pdf
7f37c0c4f98b7aca0c88a8ea24ca6fbeda7533c0e5962ef8b543a5f1af903974
pdf-embedded-file PDF EmbeddedFile object 244 at offset 0x1A9FA 310875 bytes
andromeda_neptune_673_2.pdf
0b00f28ef89d4f202159c698010a8fa3ff678b68212eb9b6c54a8bd423d88fd6
pdf-embedded-file PDF EmbeddedFile object 244 at offset 0x1A9FA 397343 bytes
stream_019_off0001a023.bin
239d316bbcec5904327bacdaf1719f0e8c982e20d83fcd7cef4a887948fd0ea4
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1A023 483886 bytes
objstm_0121_00.bin
9ed6da47923c10f83573d8ed91d6a2d8a3d49113d521ee4ef3fc6019daa6ebc8
pdf-objstm-decoded PDF /ObjStm 121 0 obj (inflated) 1129 bytes
font_00_cff_off0000b46d.bin
38d7d0627d6ef08fdb595be75f8f12752f3381fa7a1441ca8f76a5e76dc6e7b9
pdf-font-stream PDF embedded font (cff) at offset 0xB46D 609 bytes
font_01_cff_off0000ba3f.bin
5f3f348279f5218a0f3607c4a8e7c1b2190742072e04b58112191aa6b4235f52
pdf-font-stream PDF embedded font (cff) at offset 0xBA3F 886 bytes
font_02_cff_off0000c1e7.bin
7e5cb310f6cb7822b8a316192e8347738bb3f1d76fe954bdbf17623d2e87f2fb
pdf-font-stream PDF embedded font (cff) at offset 0xC1E7 3808 bytes
font_03_cff_off0000d457.bin
99bc093cddfa13f76f619bedeaf723ce24882a341f9686e35da3cad8dbab0a72
pdf-font-stream PDF embedded font (cff) at offset 0xD457 3669 bytes