Malicious PDF — malware analysis report

Static analysis result for SHA-256 83292ba7a1ddda6a…

MALICIOUS

PDF

1.22 MB Created: 2021-05-17 15:35:48 +09:00 Authoring application: Adobe InDesign CC 2017 (Macintosh) (via Adobe PDF Library 15.0)
MD5: ffe39eb91e0247fb13bd8fd8152f61a3 SHA-1: 563ba4681a2e8deab300f41410fd35ef062d8458 SHA-256: 83292ba7a1ddda6acf32181c693aa85b9e433fcb908a94ebccbed0f407a1a021
128 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File T1566.001 Spearphishing Attachment T1204 User Execution

This PDF document contains embedded JavaScript, identified by the CVE_2020_9715 heuristic, which is designed to exploit a vulnerability in Adobe Reader. The JavaScript is heavily obfuscated but appears to decode and execute a second-stage payload. The ML classifier strongly indicates malicious intent. No specific family could be identified due to the obfuscation and generic nature of the exploit.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8603

Heuristics 8

  • dataObjects ESObject stale-cache trigger — CVE-2020-9715 critical CVE exact CVE_2020_9715
    PDF embeds a file and JavaScript follows the CVE-2020-9715 ESObject use-after-free trigger shape: access this.dataObjects[], clear the dataObjects entry, schedule app.setTimeOut(), then re-access the Data ESObject through toString().
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85
    ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/exif/1.0/aux/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/t/pg/
    • http://ns.adobe.com/xap/1.0/sType/Dimensions#
    • http://ns.adobe.com/xap/1.0/g/
    • http://ns.adobe.com/illustrator/1.0/
    • http://www.adobe.com/
    • http://www.iec.ch

Extracted artifacts 14

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0388_000.js
0eef8eb51f31d05cce0b6550e13852167dd5a2ebf256a3d6ea42efcaff17d4b4
pdf-javascript-stream PDF /JS object 388 at offset 0x123A24 341509 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 6 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
stream_017_off00009c06.bin
cc6bbf33dd38942ec049869c30cc532dbc33b1d6e87913b477691e1b2d7063cf
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x9C06 6967 bytes
stream_083_off000bbda2.bin
15c786f0b8c2501eaacf62b2ee25a744f642a23f219880e6eb47c84f111ca2ee
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xBBDA2 280949 bytes
custom_b64_stage_000.js
c5aff6bf1f259b1ed76143f53dc64c661a65ab56a56c48be8efe59c807e94ba3
deobfuscated-js custom Base64 decoded JavaScript layer 1 (PDF /JS object 388) at offset 0x123ED0 255159 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 4 eval/decoder/string-building token(s).
icc_00_off00008e41.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x8E41 3144 bytes
font_00_cff_off00004822.bin
c95962a95d8ec028b4766e417ad58239112a00c7ca861f1b18a9aa782e7fa89f
pdf-font-stream PDF embedded font (cff) at offset 0x4822 20680 bytes
font_02_cff_off0000b7f2.bin
ee06021d595597294aae4201d42c5dca2789a4e6dbf7bacd49071d8238e09510
pdf-font-stream PDF embedded font (cff) at offset 0xB7F2 9583 bytes
font_03_cff_off0000d89e.bin
489e7ea8d86da8876aa082428a19fdd93ff3c2450c70f92de55f725310da4d31
pdf-font-stream PDF embedded font (cff) at offset 0xD89E 28895 bytes
font_04_cff_off00014591.bin
9003ec7cb1bb7d3c952f5ebb3732b3d76f2cadb5b7d77bcda5c8ad2d32aff1cc
pdf-font-stream PDF embedded font (cff) at offset 0x14591 39510 bytes
font_05_cff_off00075241.bin
a636da71374ec7bc18965b83adbc23903d5acafbf2a20ed106bda33ecea8d043
pdf-font-stream PDF embedded font (cff) at offset 0x75241 2614 bytes
font_06_cff_off000a398d.bin
76a94b883e88e1ff089c42cac4095f11bc6543c96cb41f29dd6490d14206f138
pdf-font-stream PDF embedded font (cff) at offset 0xA398D 3660 bytes
font_07_cff_off000af191.bin
baa23b47efe12c554a1eb11a142a609267b8c5d6878d4a23ebd335c6fe1c966e
pdf-font-stream PDF embedded font (cff) at offset 0xAF191 66991 bytes
font_09_cff_off000eb084.bin
4725853bff2c577f02b5c8dede0c03028c6a6c6695e0eb8f77447746e9156ef5
pdf-font-stream PDF embedded font (cff) at offset 0xEB084 870 bytes
font_10_cff_off000f9243.bin
585922044c3977d8b93ae227fb5fe83ec0b4e270fd2b02fed78880a6168329a4
pdf-font-stream PDF embedded font (cff) at offset 0xF9243 20975 bytes