Malicious PDF — malware analysis report

Static analysis result for SHA-256 976a036d4b45aa72…

MALICIOUS

PDF

1.95 MB
MD5: ce5f89b5441c91d1044b63cfab72579e SHA-1: 1f8f28a7a9165f739ca3b6b98c366baafe7a5ebe SHA-256: 976a036d4b45aa72c0384cba504a5c879a4cd930fc18839d8f1ae9ce5aa8743c
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript T1204.002 Malicious File

The PDF file contains embedded JavaScript, triggered by the CVE-2007-5659 vulnerability related to Collab.collectEmailInfo. Static analysis recovered deobfuscated JavaScript streams, indicating the sample's intent is to execute malicious code. The ML classifier strongly flagged this PDF as malicious, supporting the conclusion that it is designed to deliver a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659
    PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (identified after JavaScript deobfuscation)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0001_000.js
54b823c66bf0cdbeec11eb9e7f3eb04d02db004cb286b08c78209b92f9b09d9a
pdf-javascript-stream PDF /JS object 1 at offset 0xF 37 bytes
javascript_obj0013_001.js
e1c735ec368f7648d6351708dcfeaf9261abc0c0eef43cc7111d392f17623088
pdf-javascript-stream PDF /JS object 13 at offset 0x361 17136 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 4 long base64-like blob(s).
legacy_pdfkit_stage_000.js
0f6c421ec7ef0b80c35cb0287c6078a1c7657399765915dc610add3ba05127dd
deobfuscated-js reverse-string concatenation decoded JavaScript at offset 0x361 769 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).
legacy_pdfkit_stage_001.js
3dae10a7456ac4f6bf416a772242211dcfec9bf1e1d92863a3ee6d5e2a22e30a
deobfuscated-js reverse-string concatenation decoded JavaScript at offset 0x361 765 bytes
legacy_pdfkit_stage_002.js
492a67204c3b072620834e58d596177c8ffd56e3d86045d656a9cb510ea70d6a
deobfuscated-js reverse-string concatenation decoded JavaScript at offset 0x361 509 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s).