Malicious PDF — malware analysis report

Static analysis result for SHA-256 814cd5d5a013a18d…

MALICIOUS

PDF

646.1 KB Created: 2008-02-27 16:58:09 +08:00 Authoring application: PScript5.dll Version 5.2 (via Acrobat Distiller 6.0.1 (Windows))
MD5: bc5cf40afbf74342c15df1baad211e43 SHA-1: f7b558741503ba6f29af114cfd660ef19f88d054 SHA-256: 814cd5d5a013a18dc43f77a61e49decb3c6847e2fa08974704c365f4fb209e92
254 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript T1204.001 Malicious Link T1204.002 Malicious File

The PDF file contains embedded JavaScript and triggers a critical heuristic for CVE-2007-5659 (Collab.collectEmailInfo). This indicates the document is designed to exploit this vulnerability to gather user email information. The presence of an extracted JavaScript file and ClamAV detections further support its malicious nature as a dropper or exploit delivery mechanism.

Heuristics 10

  • Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659
    PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (matched in decompressed stream)
  • ClamAV: Win.Trojan.Dropper-82 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Dropper-82
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/xhtml
    • http://www.xfa.org/schema/xfa-data/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/iX/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0017_000.js
a855e1484b6aa802ce0f6f936ba6d5b5bb5556ec34d1f510cb7f17c768fa4311
pdf-javascript-stream PDF /JS object 17 at offset 0x676 4622 bytes
Detection
ClamAV: Win.Trojan.Dropper-82
Obfuscation or payload: likely
Carved artifact contains 16 eval/decoder/string-building token(s).
font_00_cff_off0008530b.bin
6f7d0254022174ff25d1f2137848b1be40a16587d2f8650e91efba0e4796e553
pdf-font-stream PDF embedded font (cff) at offset 0x8530B 2312 bytes
font_01_sfnt_off00085f97.bin
6cddcdd51335767d4015d31283ea21cea48097d60535b29e16634c1656b05874
pdf-font-stream PDF embedded font (sfnt) at offset 0x85F97 53805 bytes
font_02_cff_off0008d4d7.bin
e718e3a999849e922c215d1559efa77ce32ef8b1512401783e739efd9d2cc5a3
pdf-font-stream PDF embedded font (cff) at offset 0x8D4D7 885 bytes