Malicious PDF — malware analysis report

Static analysis result for SHA-256 a5288a919ca6a121…

MALICIOUS

PDF

69.1 KB Created: 2009-08-30 00:20:17 UTC Authoring application: AdobePS5.dll Version 5.2.2 (via Mac OS X 10.5.8 Quartz PDFContext)
MD5: 3632d9cf54b429ce0ff9d6a64d675e7e SHA-1: e5eb7a401360fef71744745144d651edbdda299e SHA-256: a5288a919ca6a12195b97b00be61103efa68f5bbdbe113bbd4feb4f42e8da861
384 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.003 Windows Command Shell T1105 Ingress Tool Transfer

This PDF file contains embedded JavaScript and an embedded PE payload, triggering critical heuristics for PDF launch actions and embedded executable payloads. The exploit targets CVE-2010-1240, which allows for command execution via a launch action. The embedded payload was detected as Win.Trojan.Rozena-131 by ClamAV, indicating it is a malicious executable. The PDF attempts to launch cmd.exe to execute the payload.

Heuristics 10

  • Adobe Reader Launch action command execution critical CVE exact CVE_2010_1240
    PDF uses the Adobe Reader/Acrobat Launch action pattern associated with CVE-2010-1240: cmd.exe is invoked with attacker-controlled parameters, paired with an embedded/exported payload.
  • Launch action critical PDF_LAUNCH
    PDF contains a /Launch action whose target is an executable, URL, or UNC path — can start an external application
  • Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOAD
    PDF stream bytes contain an embedded Windows executable with a verified PE header. Exploit chains often hide droppers inside ordinary streams rather than standard /EmbeddedFile attachments.
  • /Launch action target: cmd.exe critical PDF_LAUNCH_COMMAND
    PDF /Launch action specifies an executable target with parameters '/Q /C %HOMEDRIVE%&cd %HOMEPATH%&(if exist "Desktop\\form.pdf" (cd "Desktop"' — references a known-dangerous executable (cmd, PowerShell, etc.).
  • ClamAV: Pdf.Exploit.Agent-20881 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-20881
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0022_000.js
eff4a0943aaff2d99cb5c8666337775c91d4d5f687782df94d2c5fc77becde7f
pdf-javascript-stream PDF /JS object 22 at offset 0x886E 53 bytes
stream_003_off00003b9e.bin
c64b8ff24c6b9b4242aea784c2508ec0b14934270daf7dcb2b33c5ff8607f6a2
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3B9E 37888 bytes
Detection
ClamAV: Win.Trojan.Rozena-131
Obfuscation or payload: unlikely
icc_00_off000002d6.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x2D6 3144 bytes
font_00_sfnt_off0000d621.bin
c26d179f0b54468d3dc054d7d9c8d5b6903de3c969d44da98b5e109e58cabca6
pdf-font-stream PDF embedded font (sfnt) at offset 0xD621 41452 bytes