Malicious PDF — malware analysis report

Static analysis result for SHA-256 a922329aaab340c4…

MALICIOUS

PDF

12.2 KB Created: 2008-09-11 02:02:39 -07:00 Authoring application: Acrobat Editor 8.0 (via Adobe Acrobat 8.0)
MD5: 13bfb321a95871aea6c91ffc03aaf2be SHA-1: 8e406352be459f8d11b9d0a3a129ad47b6ab99d9 SHA-256: a922329aaab340c4eaa899696ce5de2a88088e4862ace272dd4237a8bfd27b65
118 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.001 PowerShell

The PDF file exploits CVE-2007-5659 (Collab.collectEmailInfo) to achieve arbitrary code execution. An embedded JavaScript stream was found, which is obfuscated and likely responsible for the exploit. The file also contains references to standard RDF and XMP namespaces, which are benign.

Heuristics 6

  • Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659
    PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (matched in decompressed stream)
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0052_000.js
c47d70b348c3e6fb4eeb12b43ccb28fce215697dd541fddde288685f49c52e5e
pdf-javascript-stream PDF /JS object 52 at offset 0xFE3 3528 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s).