MALICIOUS
208
Risk Score
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1566.001 Spearphishing Attachment
This PDF document contains JavaScript that displays a fake Adobe Reader update prompt to the user. The script constructs a URL, "http://cgi.adobe.com/special/acrobat/update", which is presented to the user as a download link for a necessary update. This is a common social engineering tactic to lure users into downloading and executing malicious payloads disguised as software updates. The presence of embedded files and RichMedia (Flash) further suggests a multi-stage attack.
Machine Learning
- Nyx PDF Classifier malicious score 0.9727
Heuristics 10
-
Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGEA valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
-
RichMedia (Flash) high PDF_RICHMEDIAPDF contains /RichMedia (Adobe Flash) which is a historic exploit vector (matched inside decoded stream)
-
Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
XFA form low PDF_XFAPDF uses XML Forms Architecture — can contain script logic (matched inside decoded stream)
-
Encrypted PDF (string and stream contents are opaque to static scan) info PDF_ENCRYPTEDPDF declares /Encrypt — string objects and stream contents are encrypted with the standard security handler (RC4 or AES). On its own this is informational; legitimate encrypted documents include signed contracts, billing statements, and rights-managed material. Static heuristics cannot inspect encrypted payload bytes.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
- http://ns.adobe.com/xdp/In extracted file (embedded_file_obj0011.bin)
- http://www.xfa.org/schema/xci/2.8/In extracted file (embedded_file_obj0012.bin)
- http://www.xfa.org/schema/xfa-template/2.8/In extracted file (embedded_file_obj0013.bin)
- http://www.xfa.org/schema/xfa-data/1.0/In extracted file (embedded_file_obj0014.bin)
- http://www.xfa.org/schema/xfa-locale-set/2.7/In extracted file (embedded_file_obj0015.bin)
- http://ns.adobe.com/xtd/In extracted file (embedded_file_obj0016.bin)
- http://www.xfa.org/schema/xfa-form/2.8/In extracted file (embedded_file_obj0018.bin)
Extracted artifacts 15
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_file_obj0011.bin |
pdf-embedded-file | PDF EmbeddedFile object 11 at offset 0x17CF | 163 bytes |
SHA-256: 3000b3469a8bd553f177da3f507a5ea2271a3dee1fd5d5343f41950837af583c |
|||
embedded_file_obj0012.bin |
pdf-embedded-file | PDF EmbeddedFile object 12 at offset 0x18C0 | 1670 bytes |
SHA-256: 66b82b096ae83103365f40b9b767a5582b0a497e4589e7b9323eac0320c61808 |
|||
embedded_file_obj0013.bin |
pdf-embedded-file | PDF EmbeddedFile object 13 at offset 0x1BDC | 785 bytes |
SHA-256: e763ac63c3d21786709e7f462b463575525d0e344202f42dbb96897a01541e78 |
|||
embedded_file_obj0014.bin |
pdf-embedded-file | PDF EmbeddedFile object 14 at offset 0x1DD2 | 150 bytes |
SHA-256: 720c47f19e6a058099295d18a16b7149cc73fe497eb78821ea810f3192228dc4 |
|||
embedded_file_obj0015.bin |
pdf-embedded-file | PDF EmbeddedFile object 15 at offset 0x1EA3 | 2955 bytes |
SHA-256: c8a82f67dfd8d68c2f8fe494ca2deee4604701c8f02863bf87d222b992e45de9 |
|||
embedded_file_obj0016.bin |
pdf-embedded-file | PDF EmbeddedFile object 16 at offset 0x221D | 200 bytes |
SHA-256: 4cb349134bdb5f1a1c03281df9b53128ebe947f235398a912a4f0a9f638b24d5 |
|||
embedded_file_obj0017.bin |
pdf-embedded-file | PDF EmbeddedFile object 17 at offset 0x2311 | 835 bytes |
SHA-256: 4273cd319df227c91b92e5509527bb4f6e1abfb3aa2beec2fb2adb93a8671f62 |
|||
embedded_file_obj0018.bin |
pdf-embedded-file | PDF EmbeddedFile object 18 at offset 0x24E9 | 56 bytes |
SHA-256: 4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1 |
|||
mapmo_movie.swf |
pdf-embedded-file | PDF EmbeddedFile object 71 at offset 0x678E | 15914 bytes |
SHA-256: 4970f6573a1ee1592e5a6980a13bc7a9c66af8af7099658f5e2441dcd0239f49 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
actual_type=SWF; declared_or_context_type=PDF; filename=mapmo_movie.swf; kind=pdf-embedded-file Carved SWF contains ByteArray/Loader/loadBytes staging terms. Carved artifact entropy is 7.99, consistent with packed or encrypted content.
|
|||
javascript_obj0036_000.js |
pdf-javascript-stream | PDF /JS object 36 at offset 0x2BBB | 1169 bytes |
SHA-256: 0ab3d232b2f2272b7039ee3e45d0be78ade06bb45327a799559ad4a592ef5a3d |
|||
Preview scriptFirst 1,000 lines of the extracted script
if (typeof(this.ADBE) == "undefined") this.ADBE = new Object(); ADBE.LANGUAGE = "ENU"; ADBE.Viewer_string_Title = "Adobe Acrobat"; ADBE.Viewer_string_Update_Desc = "Adobe Interactive Forms Update"; ADBE.Reader_string_Need_New_Version_Msg = "This PDF file requires a newer version of Adobe Reader. Press OK to download the latest version or see your system administrator."; ADBE.Viewer_string_Need_New_Version_Msg_Old = "This PDF requires a newer version of Acrobat. Copy this URL and paste into your browser or see your sys admin."; ADBE.Viewer_string_Need_New_Version_Msg = "This PDF form requires a newer version of Adobe Acrobat. Without a newer version, the form may display, but may not work properly. Some form elements might not be visible at all. Click OK for more information on obtaining the latest version of Adobe Reader."; ADBE.Viewer_string_Need_New_Version_Msg_Updater = "This PDF form requires a newer version of Adobe Acrobat. Without a newer version, the form may display, but may not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will download and install the latest version."; |
|||
javascript_obj0037_001.js |
pdf-javascript-stream | PDF /JS object 37 at offset 0x2DCD | 902 bytes |
SHA-256: e985b5df65c8c3cf732a9074b575fbc594c1c7f0bccc0994182ec7e5c0f7308a |
|||
Preview scriptFirst 1,000 lines of the extracted script
if (typeof(ADBE.Reader_Value_Asked) == "undefined")
ADBE.Reader_Value_Asked = false;
if (typeof(ADBE.Viewer_Value_Asked) == "undefined")
ADBE.Viewer_Value_Asked = false;
if (typeof(ADBE.Reader_Need_Version) == "undefined" || ADBE.Reader_Need_Version < 9.0)
{
ADBE.Reader_Need_Version = 9.0;
ADBE.Reader_Value_New_Version_URL = "http://cgi.adobe.com/special/acrobat/update";
ADBE.SYSINFO = "?p=" + app.platform + "&v=" + app.viewerVersion + "&l=" + app.language + "&c=" + app.viewerType + "&r=" + ADBE.Reader_Need_Version;
}
if (typeof(ADBE.Viewer_Need_Version) == "undefined" || ADBE.Viewer_Need_Version < 9.0)
{
ADBE.Viewer_Need_Version = 9.0;
ADBE.Viewer_Value_New_Version_URL = "http://cgi.adobe.com/special/acrobat/update";
ADBE.SYSINFO = "?p=" + app.platform + "&v=" + app.viewerVersion + "&l=" + app.language + "&c=" + app.viewerType + "&r=" + ADBE.Viewer_Need_Version;
}
|
|||
javascript_obj0038_002.js |
pdf-javascript-stream | PDF /JS object 38 at offset 0x2F24 | 1363 bytes |
SHA-256: 529357503ec67b623d2a12816cdeea62bd639f2b4ff4e568b01c96cc3f5bfc6f |
|||
Preview scriptFirst 1,000 lines of the extracted script
if (typeof(xfa_installed) == "undefined" || typeof(xfa_version) == "undefined" || xfa_version < 2.8)
{
if (app.viewerType == "Reader")
{
if (ADBE.Reader_Value_Asked != true)
{
if (app.viewerVersion < 9.0)
{
if (app.alert(ADBE.Reader_string_Need_New_Version_Msg, 1, 1) == 1)
this.getURL(ADBE.Reader_Value_New_Version_URL + ADBE.SYSINFO, false);
ADBE.Reader_Value_Asked = true;
}
else if (app.alert(ADBE.Viewer_string_Need_New_Version_Msg_Updater, 1, 1) == 1)
app.findComponent({cType:"Plugin", cName:"XFA", cVer:"2.8"});
}
}
else
{
if (ADBE.Viewer_Value_Asked != true)
{
if (app.viewerVersion < 7.0)
app.response({cQuestion: ADBE.Viewer_string_Need_New_Version_Msg_Old, cDefault: ADBE.Viewer_Value_New_Version_URL + ADBE.SYSINFO, cTitle: ADBE.Viewer_string_Title});
else if (app.viewerVersion < 9.0)
{
if (app.alert(ADBE.Viewer_string_Need_New_Version_Msg, 1, 1) == 1)
app.launchURL(ADBE.Viewer_Value_New_Version_URL + ADBE.SYSINFO, true);
}
else if (app.alert(ADBE.Viewer_string_Need_New_Version_Msg_Updater, 1, 1) == 1)
app.findComponent({cType:"Plugin", cName:"XFA", cVer:"2.8"});
ADBE.Viewer_Value_Asked = true;
}
}
}
|
|||
objstm_0047_00.bin |
pdf-objstm-decoded | PDF /ObjStm 47 0 obj (inflated) | 2543 bytes |
SHA-256: 856830b101f28eaa61f2ccb44204fecaa2d0a9658055009fda363a9d3056ff76 |
|||
polyglot_child_pdf_off0000f48b.pdf |
polyglot-child-pdf | Secondary PDF body inside pdf container at offset 0xF48B | 239199 bytes |
SHA-256: 366dd783226a7b7343e9927af00643a697569690e6013ccb5ea3170cf4cd28e3 |
|||
polyglot_child_pdf_off000482fb.pdf |
polyglot-child-pdf | Secondary PDF body inside pdf container at offset 0x482FB | 6127 bytes |
SHA-256: 9a95102ad6b4d58a9a742832f61490a27e9b62855fe295b13214addfda321ad3 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.