Malicious PDF — malware analysis report

Static analysis result for SHA-256 76589ef162daa07d…

MALICIOUS

PDF

264.4 KB Created: 2010-04-21 00:46:53 +08:00 Authoring application: Adobe Acrobat 9.3.2 (via Adobe Acrobat 9.3.2 Image Conversion Plug-in)
MD5: e559f8d3fb9f971b8158ee9cea7da5b6 SHA-1: 643d046534c1d1c1e777e4492c9cc3bf9fbca52e SHA-256: 76589ef162daa07d1b232a6b8d952299dfa007e336bac342a5365d40654953b9
220 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file contains embedded JavaScript and a Flash object, both of which are flagged as malicious. ClamAV detections indicate it is a dropper and exploit, likely designed to download and execute a second-stage payload. The ML classifier also strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 9

  • ClamAV: Pdf.Dropper.Agent-7273895-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7273895-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/exif/1.0/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
pad.swf
c8a20e8ded0e5fe8a6a5cddff2408ac7f8a83df3f18abea5748cc817f3a3ebb9
pdf-embedded-file PDF EmbeddedFile object 1 at offset 0xFA 26810 bytes
Detection
ClamAV: Pdf.Exploit.Agent-35955
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
javascript_obj0007_000.js
e8f5d8f2ef38ed2de1948a2423257a50d6db6e6a3121fe4019594411e6913d51
pdf-javascript-stream PDF /JS object 7 at offset 0x781C 2617 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
javascript_obj0007_001.js
d01f3e1ecf31b3799f38229fdee63e895d3eea43c48fb78de52563f80e569b3b
pdf-javascript-stream PDF /JS object 7 at offset 0x783F 239945 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).