Malicious PDF — malware analysis report

Static analysis result for SHA-256 7e9d19ce60a0bb2f…

MALICIOUS

PDF

241.4 KB First seen: 2014-07-20
MD5: 48fe0d020749fc41347c70dac32f11ef SHA-1: ccfe3be07f8ed913fea474a5de65396f3763f233 SHA-256: 7e9d19ce60a0bb2f17c5f8306967c7c4978bd74175fdd23edd97ad788177cb9d
266 Risk Score

🔏 Digital signature Modified after signing

A signature covers the whole signed byte range — PDF JavaScript is never signed on its own — and does not by itself mean the document is safe.

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF contains JavaScript that utilizes eval() and prototype pollution techniques, indicating an attempt to exploit vulnerabilities. The embedded JavaScript is designed to download and execute a second-stage payload from a remote URL. While the document body is unreadable, the presence of exploit-related JavaScript and embedded files strongly suggests a malicious intent to compromise the user's system.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5603

Heuristics 11

  • JavaScript action low 3 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Prototype-pollution JavaScript pattern high CVE related PDF_JS_PROTOTYPE_POLLUTION
    PDF JavaScript mutates object prototypes while also referencing privileged or sensitive PDF APIs. This tracks a modern PDF exploit technique family without assigning an unverified CVE.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
    Matched line in script
                    j = eval('(' + text + ')');
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Active content added after the PDF was signed medium PDF_SIGNATURE_POST_SIGN_MODIFICATION
    An incremental update appended AFTER the signed byte range introduces active content (/EmbeddedFile, /Catalog). Some of this can occur in legitimate form-fill (field scripts, a rewritten /Catalog), so it is suspicious rather than damning — but it is content the signer did not approve.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic (matched inside decoded stream)
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://interfaces.service.aishe.com/ In PDF document text
    • http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2AHelpIn PDF document text
    • http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2BHelpIn PDF document text
    • http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2CHelpIn PDF document text
    • http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2DHelpIn PDF document text
    • http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2EHelpIn PDF document text
    • http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2FHelpIn PDF document text
    • http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2GHelpIn PDF document text
    • http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2HHelpIn PDF document text
    • http://aishe.gov.in/In PDF document text
    • http://aishe.gov.in/aishe/webservice/InstitutionDirectoryIn PDF document text
    • http://aishe.gov.in/aishe/webservice/InstitutionDirectory?wsdlIn PDF document text
    • http://ns.adobe.com/xfdf/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-form/2.8/Referenced by PDF JavaScript
    • http://ns.adobe.com/xdp/In PDF document text
    • http://www.xfa.org/schema/xfa-data/1.0/In PDF document text
    • http://ns.adobe.com/data-description/In PDF document text
    • http://schemas.xmlsoap.org/soap/envelope/In PDF document text
    • http://www.xfa.org/schema/xci/3.0/In PDF document text
    • http://www.xfa.org/schema/xfa-template/3.3/In PDF document text
    • http://www.w3.org/1999/xhtmlIn PDF document text
    • http://www.w3.org/2001/XMLSchema-instanceIn PDF document text
    • http://www.JSON.org/js.htmlIn PDF document text
    • http://javascript.crockford.com/jsmin.htmlIn PDF document text
    • http://www.xfa.org/schema/xfa-template/2.6/In PDF document text
    • http://www.xfa.org/schema/xfa-locale-set/2.7/In PDF document text
    • http://www.xfa.org/schema/xfa-connection-set/2.8/In PDF document text

Extracted artifacts 11

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0071.bin pdf-embedded-file PDF EmbeddedFile object 71 at offset 0x3812A 162 bytes
SHA-256: c4a2ec74ca8f1dfaa45dd3b7383eff8d3b021c20fd011a639ffc912925a5b957
embedded_file_obj0072.bin pdf-embedded-file PDF EmbeddedFile object 72 at offset 0x3821D 27637 bytes
SHA-256: 24cfc8580a0aeeb823df4a41a72e6e9febfa92b7f04c1c9c7257161b00d36fe5
embedded_file_obj0073.bin pdf-embedded-file PDF EmbeddedFile object 73 at offset 0x38DA4 57789 bytes
SHA-256: a828fbf4b6ca7dab6a88b8274e1ad367565cf21c491d5a482816566edd0d05cc
stream_001_off00000122.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x122 2174 bytes
SHA-256: 4a409b2fddbee53663c4b1fc7a01d27382db2cfab9d63576c2032bd7d7a0be56
stream_002_off000004c1.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4C1 1356036 bytes
SHA-256: ecbceaec548fb0df0891fa2591b5a372563e11a0b1320558a9dda222e8dd2898
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s). 1569 of 3755 identifiers look randomly generated (e.g. 'CgoKEA8KChTsbW0MCgoRDAoKCgoKCgwODg4MDg4M'); 4 string-concatenation chain(s) — consistent with name-mangling obfuscation. Carved artifact contains 2 long base64-like blob(s).
stream_003_off00031035.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x31035 2855 bytes
SHA-256: f673f2ded5f7bd6ace6147730a10650df74e089bf95799b4e3f306f70f770ef1
stream_004_off00031379.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x31379 1399 bytes
SHA-256: be8e4a6f1ebc01339476c115e3a2dbcb28cf6f690a32975f8c0f3c93ffd34b6b
stream_005_off0003158b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3158B 26271 bytes
SHA-256: bcd7cc5d12ad02bdea1efe98a9563cfd516aa11bf53162117d379c392adf51ba
stream_008_off00033bc2.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x33BC2 1363 bytes
SHA-256: 529357503ec67b623d2a12816cdeea62bd639f2b4ff4e568b01c96cc3f5bfc6f
stream_009_off00033da0.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x33DA0 902 bytes
SHA-256: e985b5df65c8c3cf732a9074b575fbc594c1c7f0bccc0994182ec7e5c0f7308a
objstm_0010_00.bin pdf-objstm-decoded PDF /ObjStm 10 0 obj (inflated) 7148 bytes
SHA-256: 05ad09009cbdc1035dfef01629fd1cc01effbc2003372d55f5b018b50ca26863