Malicious PDF — malware analysis report

Static analysis result for SHA-256 a64b4946fb146239…

MALICIOUS

PDF

137.8 KB Created: 2008-05-21 16:10:52 +08:00 Authoring application: Acrobat PDFMaker 6.0 for Word (via Acrobat Distiller 6.0 (Windows))
MD5: 6917cc79ed287f12c49851dbd0791316 SHA-1: 316a9cb03653a3cc8fe8f7aef32d895c5fc0107b SHA-256: a64b4946fb1462393a8a50dd67acfbd3e83f64fa3620aa36d4896ff48ca4012e
72 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File T1566.002 Spearphishing Attachment

This PDF file contains embedded JavaScript and an embedded PDF, both of which exhibit suspicious static findings. The primary PDF appears to be a lure, potentially for a phishing or social engineering attack, given the presence of embedded executable content. The embedded JavaScript and secondary PDF are likely responsible for initiating the malicious payload delivery, possibly by exploiting a vulnerability within the PDF reader or by tricking the user into opening the embedded file.

Heuristics 6

  • Secondary embedded PDF body has suspicious static findings high POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/xhtml
    • http://www.xfa.org/schema/xfa-data/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/iX/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/pdfx/1.3/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0026_000.js
c1d988221c2254fe65d5ba1bd3fa29e4231ac08bae1d79d26f385a8eba4cbfc7
pdf-javascript-stream PDF /JS object 26 at offset 0xA9E 1152 bytes
polyglot_child_pdf_off0001a523.pdf
884bc9ef50dd77b43c3f9142dc512c54bfe07df64777a940c578c16a821da8c8
polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x1A523 33263 bytes