Malicious PDF — malware analysis report

Static analysis result for SHA-256 86210630d56cbdc8…

MALICIOUS

PDF

125.6 KB Created: 2011-09-23 16:22:29 +02:00 Authoring application: Acrobat PDFMaker 9.1 für Word (via Adobe PDF Library 9.0)
MD5: 1b30a77cd4a02afc983b9a653646649c SHA-1: ea5bdebf21fd88c46d1555f6bf1b76e5bda2d9e9 SHA-256: 86210630d56cbdc89f1d1a763d638c447ff912779d544f707ac8afde53413ab1
158 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

This PDF document contains embedded JavaScript that triggers form submission actions. The script is designed to prompt the user for identity information, such as name and email, before submitting the form. This behavior, combined with the PDF's structure suggesting a workflow, indicates a phishing or credential harvesting attempt, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6415

Heuristics 7

  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/pdfx/1.3/
    • http://ns.adobe.com/AcrobatAdhocWorkflow/1.0/
    • https://share.acrobat.com/.docid/C0ceyFpEAW2LzZ5YAD8*oQ:jjyxXBW6*nw4mXB87kdhyA

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0327_000.js
4a3be1c97fa660c78458adbf8467d9ef0ece4b4be6574ddb6a76861e566be29f
pdf-javascript-stream PDF /JS object 327 at offset 0x1C144 999 bytes
javascript_obj0335_001.js
62515759168808052d15d016872a16e6ff42a85ac749a3c18a6be477049d8394
pdf-javascript-stream PDF /JS object 335 at offset 0x3A08 11553 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).
javascript_obj0371_002.js
9dd64f510230f902f7af6abae037ec918dd8fa478706725b4ae0e25e6a7effc5
pdf-javascript-stream PDF /JS object 371 at offset 0x963F 2832 bytes
stream_019_off0000dcb1.bin
0561be411d543e73b7e33c3c6ad7a6aec3b785a014adf5d509455e5c655439c1
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xDCB1 61043 bytes
icc_00_off00007174.icc
653b586c4707574ffcd648ba35494daed2c76ceafcf4c07d315ed961b1dc347f
pdf-icc-profile PDF ICC profile at offset 0x7174 408 bytes