Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d0bcd8709f2c1ae…

MALICIOUS

PDF

21.1 KB
MD5: 925aebb0342821170e060e4316433a7b SHA-1: 772ebf1addd6a4f4f79918a0e6590c46b76c57f2 SHA-256: 7d0bcd8709f2c1aed6c627496ab5b542fe77a8e9d750041b8dd709e590df74ea
118 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.001 Malicious Link T1059.007 JavaScript

The PDF file contains embedded JavaScript that leverages the CVE-2007-5659 vulnerability (Collab.collectEmailInfo). The JavaScript is heavily obfuscated but appears to be designed to download and execute a second-stage payload. The use of eval() and unescape() functions, along with string concatenation to hide malicious code, is characteristic of exploit kits attempting to bypass detection. The extracted JavaScript streams and deobfuscated files confirm the presence of exploit code.

Heuristics 5

  • Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659
    PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (identified after JavaScript deobfuscation)
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj111711_000.js
2b85467c37f1b3989797be83b131330beec64f060aada1002cf5ab5f3da93adc
pdf-javascript-stream PDF /JS object 111711 at offset 0x18E 3128 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 5 long base64-like blob(s).
javascript_obj111712_001.js
614078d4db662398d8eb36d6412236f4e3959fa630f609191019f030eef0acf9
pdf-javascript-stream PDF /JS object 111712 at offset 0xDFC 16360 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 6 long base64-like blob(s).
javascript_obj111713_002.js
2810ff4c38e0e89642d66db5501ef248a7392de27ad00f2203c34a40d9a1cadc
pdf-javascript-stream PDF /JS object 111713 at offset 0x4E1A 1514 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 6 long base64-like blob(s).
legacy_pdfkit_stage_000.js
3d262e9b2231d9eeca68d7b0f18e2d2862f73023d7b22655cf3823e2b5c307aa
deobfuscated-js multi-marker percent-array decoded JavaScript at offset 0xDFC 1477 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s).
legacy_pdfkit_stage_001.js
893b6a69a6b1f96ef94da875e2c6de5a6ab10d72b7676187c78f81073910b29c
deobfuscated-js multi-marker percent-array decoded JavaScript at offset 0x4E1A 80 bytes
legacy_pdfkit_stage_002.js
b264b7176a6472537fc726515b7043b57ca33b4f321c709f2629bb5561f59005
deobfuscated-js multi-marker percent-array combined decoded JavaScript at offset 0xDFC 1558 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s).