Malicious PDF — malware analysis report

Static analysis result for SHA-256 7fc341dae46b4858…

MALICIOUS

PDF

107.4 KB Created: 2018-06-12 09:41:10 -04:00
MD5: a2ceb285b72708653d1b026e3849f05b SHA-1: dd3e13e6a6e9685364dd4d2d8a088637725adeb1 SHA-256: 7fc341dae46b4858e0ae597bc72bf3256507414e267e0dd10ed7071cd86dce23
200 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains embedded JavaScript that triggers an alert box mimicking an Adobe Acrobat update prompt. This script also attempts to submit form data to a suspicious URL, likely to download a second-stage payload. The use of JavaScript and the deceptive update lure are strong indicators of a malicious document designed to exploit user trust.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9477

Heuristics 9

  • PDF auto-runs JavaScript form submission on open critical PDF_OPENACTION_JS_SUBMITFORM
    PDF uses /OpenAction to run JavaScript that calls submitForm() with an external HTTP(S) URL. Opening the document triggers the outbound submission path without requiring a normal link click.
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • PDF JavaScript shows fake Acrobat updater prompt high PDF_FAKE_ACROBAT_UPDATE_LURE
    PDF JavaScript displays Acrobat/update-themed language such as a document rendering engine update or remote connection to Adobe servers. When paired with JavaScript or external submission, this is a social-engineering lure rather than benign document text.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://token.onelogin.com-token-auth.com/XVTIxaFpFSllhbFIzZW5kV1ZYRXZTVWRxT1hWMVRtaHVUMHhxTmxJM01qTlZlVWRRUkRoUVUyOXdTamQwU0doek0xUjRTMWgzYVcxbFZIRllVMVJyUVdodFpHNDVXbmRwUVhaNlkza3ZNa0l3ZEdvdldscGFVemRoYzAxVU1Xc3ZaeXRtZFc4dlF6azNVVWs5TFMwclMxVXdZak5RZERaSVowWlZUSE5tY1hneGRqaFJQVDA9LS1mZTVlNWY4ZWRiYTBjNjVkNjFiYjA2NmY2YjZmYzJlNzk0Yjg0OWNi?cid=891177979#FDF
    • https://token.onelogin.com-token-auth.com/XUlVsNFNYbFNaVXc0VVdKaWIwbFZNelZGU0hSWFVqZEtUM2xHU25WaVdFczRNa2xFUTNsalVIbEZObVI2U0d4clVraElVM0JXUVRCTWFUTTRjMWgyZFRGbmRFNVJiVzlwUXpObU1IVXdVbE5uUlhkNFEwOVhaRTFhZUd3Mk1FRkhaV3dyWWtsQ09YUkdRbGRhZEV0bmFreDZObXh5WVZCc1dXZEtWQ3RSZVhJMGJGaGxhVlk1YkVZeVMzQjJUbHBxY21SVGRsbG5NVk5vUzFWM1RXUm5WVm8xZFhwTmFqQjRSa2RaUFMwdFIyVlNPVkkwTjA5U1RFdzFXRmc0U0UxdFFqbGlRVDA5LS1kMjdiM2ZlMjM2MjhkOWQ3NGU3MjNmYjQwOGY3OGIzNTQ4NDQ3NDk5?cid=891177979
    • https://token.onelogin.com-token-auth.com/XZGxob1NUbHFaa1JIVG5SdGRFSXlUMEZRTm5Rdkx6aFRlV2hyU2xkT2QzTkJPWHBqYWxSS2JFOVBhV3hUVkROc2NFaGpRbGt6ZDNKVWRXMUVhbWRzVVhaaGMydDJja3BKVUhFMmFXUkZORmRTU1hGc1EwZGthRzVMVHpVeFNsTXllSGd3T1ZGbWFtYzFPRGN2YUdoSlRuRXZiVzV5ZDJGS1pGRnNaWEZaYTNacmRIRjJSek00VTJJMk15ODRkek4wZHpCcU1uWkVRVFV5TUd0M2FYZFdhMHMxYm1abUwwcDVWWGd3UFMwdGNGVjZNa1JETTBsWldGY3liQ3R1V0VaeVNXWkdVVDA5LS0wYzJlYjhlOWE1YWIwMmFlZWJiYTM3MGVkNWJlMDY0ZmI4MjYyMDIx?cid=891177979
    • https://token.onelogin.com-token-auth.com/XY0ZSSFkyNTJReXN6U0ZOT1JYRXlkMWRNUmxvdk16Y3lRMko2UXpkR1NEazFaa1I2WWxwd1kxcHlRV0ZHTVhnM1NuRXZhRWxHV21oVE5GVmlXVGg1ZVdGak1EUnFia1p4VkZJMmJsSkNkM0IzZEdReFNUQjJWMnBtVGxOdmNqUkxUazlMT1RSM1ZWQk1WVTFOUkU1MFlYUXJibTg1WkhwSVdFWjZhVFJGV210alJtVkVaSGRhV25aelRXOWpRV3RKZG1oaFNtaDNPRUZvWlhKSlJUZEVjbXBIYWpRelV6VlBhRlpyUFMwdE4xYzJaRFZtWjFSd2J6SmhiMk5JUldOM2EzZHFVVDA5LS1mYmQyMDFkNmM5MWZhZDgzYTJhMzVkZmMzZWQyMjk5ZTU1OTg0NmVk?cid=891177979
    • https://token.onelogin.com-token-auth.com/XUlVsNFNYbFNaVXc0VVdKaWIwbFZNelZGU0hSWFVqZEtUM2xHU25WaVdFczRNa2xFUTNsalVIbEZObVI2U0d4clVraElVM0JXUVRCTWFUTTRjMWgyZFRGbmRFNVJiVzlwUXpObU1IVXdVbE5uUlhkNFEwOVhaRTFhZUd3Mk1FRkhaV3dyWWtsQ09YUkdRbGRhZEV0bmFreDZObXh5WVZCc1dXZEtWQ3RSZVhJMGJGaGxhVlk1YkVZeVMzQjJUbHBxY
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/exif/1.0/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
1892ef6cef6a845dd8f591c8efb2ac6bbf61d36dd497264d2fea69e0e18a56da
pdf-javascript-stream PDF /JS object 12 at offset 0x180A 611 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
javascript_obj0012_001.js
e4e56e336c848f9f7151c609cc6cc263a8beeb2c466aec935a981f9f6413a089
pdf-javascript-stream PDF /JS object 12 at offset 0x1831 103766 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 8 long base64-like blob(s).
font_00_cff_off0001967b.bin
9340d372ad75a105fdb1627a30e96f892e0dc7d9588c0150cf06b4fa72281cc0
pdf-font-stream PDF embedded font (cff) at offset 0x1967B 4575 bytes