Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f32aae73e4a7015…

MALICIOUS

PDF

20.4 KB
MD5: 7b2b655e4e31a5758348498976a175ea SHA-1: 10de8ad4bd0915f1ba1940f015dcf4ac07e9af47 SHA-256: 9f32aae73e4a7015b629957052fdd94149f5c606a0322cc6a72088bcf060f6b1
118 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.001 Malicious Link

The PDF file contains embedded JavaScript that utilizes the eval() function and the CVE-2007-5659 vulnerability (Collab.collectEmailInfo). The JavaScript is heavily obfuscated, but the presence of eval() and the specific CVE exploit indicate an attempt to execute arbitrary code. This is likely intended to download and execute a second-stage payload from a remote source, a common technique for initial access.

Heuristics 5

  • Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659
    PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (identified after JavaScript deobfuscation)
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj111711_000.js
8c054f449eb1bced730b81f1b5590ec274caef2463c9dd77ce6add92b8937eed
pdf-javascript-stream PDF /JS object 111711 at offset 0x18E 3358 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 5 long base64-like blob(s).
javascript_obj111712_001.js
e29a241163c5d6e048482b4dab55885cb4cd8f01d3728193e8586df296595a41
pdf-javascript-stream PDF /JS object 111712 at offset 0xEE2 15296 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 5 long base64-like blob(s).
javascript_obj111713_002.js
036229b558d631f2e6b741a47417331303393990959fc1c0fc18bfa04d47a748
pdf-javascript-stream PDF /JS object 111713 at offset 0x4AD8 1664 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 6 long base64-like blob(s).
legacy_pdfkit_stage_000.js
ec56b382ff6c96d3ba9637e1f919996bb21c574a0be796ecf913e3ef592c4072
deobfuscated-js multi-marker percent-array decoded JavaScript at offset 0xEE2 1472 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s).
legacy_pdfkit_stage_001.js
66201566cb7b94b96d78c07e61c80e11578b5125ea85cc864e3cc788698af3dd
deobfuscated-js multi-marker percent-array decoded JavaScript at offset 0x4AD8 79 bytes
legacy_pdfkit_stage_002.js
17d523c7015a1b1736315cf7081df298ee1fdf34d1627e7ee8399ecc9ed4f040
deobfuscated-js multi-marker percent-array combined decoded JavaScript at offset 0xEE2 1552 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s).