Malicious PDF — malware analysis report

Static analysis result for SHA-256 a7876d96364292ec…

MALICIOUS

PDF

54.0 KB Created: 2011-05-17 09:05:47 Authoring application: Joomla! 1.5 - Open Source Content Management (via TCPDF 3.0.015 (http://www.tcpdf.org))
MD5: 40d01a6fbc51df7c3b5938a99c1b3540 SHA-1: fd5c3f58a0a9c4686221a368822a13c39ab19b17 SHA-256: a7876d96364292ecb5ae33d3ed595ec86afaa3166fdb0ac58f26e1959aced161
62 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.001 PowerShell

The PDF file contains a marker for the CVE-2008-2551 exploit, which is known to download and execute arbitrary files. The heuristic analysis confirms the presence of this exploit. The embedded URL 'http://artisanballoonz.com/system/system.exe' is highly suspicious and likely serves as the download location for the secondary payload. The document body, though heavily obfuscated, contains references to URLs that are typically used in phishing or malware delivery schemes.

Heuristics 3

  • C6 Messenger DownloaderActiveX exploit critical CVE exact CVE_2008_2551
    PDF stream bytes contain HTML/ActiveX content configuring the vulnerable C6 Messenger DownloaderActiveX control with propDownloadUrl and propPostDownloadAction=run. This is the published exploit shape for CVE-2008-2551.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://artisanballoonz.com/system/system.exe
    • http://www.irna.ir/View/FullStory/?NewsId=1027286
    • http://www.presstv.ir/Persian.aspx?id=8820
    • http://c6.community.alice.it/download/DownloaderActiveX.cab#Version=1,0,0,1

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off0000198f.bin
80ce46be3b4d5733393d911e720cc341eac961413bc8841086c1643fee9fc14b
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x198F 73272 bytes