Malicious PDF — malware analysis report

Static analysis result for SHA-256 9514d0478875cb04…

MALICIOUS

PDF

778.7 KB Created: 2002-12-12 17:34:08 -07:00 Authoring application: Adobe Illustrator 10.0 (via Adobe PDF library 5.00)
MD5: 87887b1b727f65bc21846da0b0f58b70 SHA-1: 21410019f3f9f7b21c4186bc6e2c41fe31ec2a63 SHA-256: 9514d0478875cb04cfdbb129e7dded67f6d7d599733095a39bc8737a1016febf
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1105 Ingress Tool Transfer

The PDF file contains an embedded Windows executable payload and a secondary embedded PDF with suspicious findings, including a PE payload. This indicates the PDF is designed to deliver malware. The embedded artifacts are the primary indicators of this malicious activity.

Heuristics 3

  • Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOAD
    PDF stream bytes contain an embedded Windows executable with a verified PE header. Exploit chains often hide droppers inside ordinary streams rather than standard /EmbeddedFile attachments.
  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/iX/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://news.bbc.co.uk/go/rss/-/2/hi/uk_news/politics/8539619.stm
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#_44

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_0009c000.exe
ea78bc403d36490b440905225bc3a165448a462241389dd1c426dfe9b17a5a1d
embedded-pe PDF raw stream PE payload at offset 0x9C000 157890 bytes
polyglot_child_pdf_off00082000.pdf
c12f18f8c9adfa0c3f9cb6f2c05cd2028386f0b1ec5b212e479a200114268610
polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x82000 264859 bytes