Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa3daa0d026bad42…

MALICIOUS

PDF

783.0 KB Created: 2010-09-11 23:35:31 Authoring application: Advanced PDF Repair at http://www.datanumen.com/apdfr/
MD5: 7ce65e9f637e70084d68e75aa4689880 SHA-1: 6b1fc1e98e556b3b52619e27e2f0d3246dd221ec SHA-256: aa3daa0d026bad42523d25333fc1ae2d7c174c70ae295b37b360d15c0bcf6339
94 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file exhibits multiple heuristic firings related to embedded JavaScript and suspicious PDF structures, including an embedded secondary PDF. The presence of JavaScript actions and streams strongly suggests an attempt to execute malicious code. While the specific payload is not immediately clear from the static analysis, the overall pattern points to a malicious PDF designed to exploit vulnerabilities or download further malware. The embedded URL is likely part of the lure or infrastructure.

Heuristics 7

  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.datanumen.com/apdfr/

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0040_000.js
a4c81d522e684fc51b77a224dadfc0bc99dcaf2031825c8a4560928ecfec3f71
pdf-javascript-stream PDF /JS object 40 at offset 0x20DA 12401 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).
stream_001_off00000aef.bin
0f910ffeec733940f6ba1ae41dc6770eab5d615c05bccc95197878b62c8dc45f
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xAEF 2928 bytes
stream_002_off00000e4d.bin
29cf1edfedd4f27f3c450646c5dc2510e6bf9e63eee1cd436ac517a465a2e1bf
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xE4D 1650 bytes
stream_003_off000011bc.js
672d461752be4a970c8e9721164ce074d252b55d09d46cc09259d2ce4fc09f7f
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x11BC 1546 bytes
stream_010_off00005a6c.bin
fe122a09d8a0444608fdc5a6f4981a2dbd469f5bbfacb4bdd327c28ccc343e13
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5A6C 149 bytes
stream_011_off00005b20.bin
4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5B20 56 bytes
font_00_cff_off000083e8.bin
ea8f409c7366ed46eeb553aa7b404f04641f482ba88463fbe253da60be5787e5
pdf-font-stream PDF embedded font (cff) at offset 0x83E8 1138 bytes
polyglot_child_pdf_off0003c00f.pdf
fe62c9c4011d1636e38d05de8e59af8334ac31e31b2d833bfeff63eecde9d7db
polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x3C00F 556059 bytes