Malicious PDF — malware analysis report

Static analysis result for SHA-256 b11e24cd061c03eb…

MALICIOUS

PDF

2.3 KB
MD5: ff8e66f831dfda6c92c28068afbeb459 SHA-1: 339acead76a45e1650f3f734537a56e958ca66d4 SHA-256: b11e24cd061c03ebf1d12075c2b44b5423bcff7dd7e2522c91f7ae1bc10f70aa
118 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious File

This PDF file contains embedded JavaScript, which is a common technique for delivering malicious payloads. The critical heuristic firing for CVE-2008-2992 indicates the exploitation of a known PDF vulnerability. The presence of multiple JavaScript streams, including one with significant obfuscation, suggests an attempt to download and execute a secondary stage. The unescape() call further supports the obfuscation and dynamic loading of malicious code.

Heuristics 5

  • util.printf — CVE-2008-2992 critical CVE exact CVE_2008_2992
    PDF JavaScript calls util.printf() — CVE-2008-2992 is a stack buffer overflow in Adobe Reader triggered by a long format-specifier argument. Widely exploited in the wild after disclosure. (matched in decompressed stream)
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj263984_000.js
a28216d626f7126644b51b686154a30f5573c63e7c7dc4d180187e01ae9192e8
pdf-javascript-stream PDF /JS object 263984 at offset 0x197 6990 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 3 long base64-like blob(s).
javascript_obj263985_001.js
37272d81e4acf99cd11523b0b446ac52bb685f75fb5bdad399dc79d64dc090b8
pdf-javascript-stream PDF /JS object 263985 at offset 0x6D5 159 bytes
javascript_obj263986_002.js
04b971d9a30fddcc5d2b09ef82949702b540464f0b4667cd9ca18783feffcf95
pdf-javascript-stream PDF /JS object 263986 at offset 0x7AB 524 bytes