Malicious PDF — malware analysis report

Static analysis result for SHA-256 828467706b263253…

MALICIOUS

PDF

9.1 KB Created: 2013-06-03 21:01:03 -02:00 Authoring application: htmldoc 1.8.23 Copyright 1997-2002 Easy Software Products, All Rights Reserved.
MD5: 4ca6c50b070a5b396837dc6d90b26714 SHA-1: 1be7b1069da38b04dd3bc7821a8b469d59bd554b SHA-256: 828467706b26325343a4f495ed10a35dc8b883c72b49b33f3c7b224ab3ed609a
114 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059 Command and Scripting Interpreter

The PDF document contains a malicious URI that attempts to exploit command interpreter path vulnerabilities, specifically targeting 'calc.exe' via 'cmd'. This is supported by heuristics indicating dangerous URI commands and the presence of 'cmd' in the document text. The reconstructed malicious URI is mailto:test%../../../../windows/system32/calc.exe".cmd, which is a strong indicator of command execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8822

Heuristics 4

  • PDF URI references command interpreter path high PDF_DANGEROUS_URI_COMMAND
    PDF contains a /URI action whose target uses a mailto/path traversal shape and references a command interpreter or scripting host. This is not a normal web link and matches legacy PDF command execution/dropper lures.
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2007-10/msg00093.html
    • http://secdev.zoller.lu
    • http://lists.grok.org.uk/full-disclosure-charter.html
    • http://www.derkeiler.com/Mailing���Lists/Full���Disclosure/2007���10/msg00093.html
    • http://lists.grok.org.uk/full���disclosure���charter.html
    • http://secunia.com/