Malicious PDF — malware analysis report

Static analysis result for SHA-256 b9b9303d0dc7f78d…

MALICIOUS

PDF

415.2 KB Created: ”¶ïB¬½þIóH}´;ñ5ûHÜ ½CË¢¤uÛu1]§Ûx6ƒÂµðAà Authoring application: }ã^Ý¿g4l–QZ½‹ðØ Cé1¢ !Üt©ÝUֆh‹»ÁDZÿà½F (via KÂíªè;ÎañÚÓ´†e÷¯WÒ}1ÙûÅHôrQu” P¢4—!{#M€ë­¯)
MD5: 62bf2e0b1b14a0d8ec1dc0ffbb44e812 SHA-1: 2959a34a962298d3c66d81d9f5aa8abcc62a78e5 SHA-256: b9b9303d0dc7f78dbe8fd2262410c69c4978c41bc3a56129bb059b27b4c812a1
276 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1559.002 Component Object Model Hijacking

The PDF file contains embedded JavaScript and RichMedia (Flash) content, and is flagged as encrypted with JavaScript. Heuristics indicate exploitation of CVE-2011-2462, which targets Adobe Reader's U3D and RichMedia parsers. This suggests the file is designed to deliver a payload by exploiting these vulnerabilities upon opening in a vulnerable reader.

Heuristics 11

  • Adobe Reader U3D/RichMedia parser exploit critical CVE likely CVE_2011_2462
    PDF combines U3D 3D content with RichMedia/Flash activation and JavaScript/action surfaces. This is the U3D RichMedia exploit document shape associated with CVE-2011-2462.
  • U3D/3D content in PDF — Adobe Reader 3D parser CVE-family indicator high CVE related PDF_U3D_CVE_RELATED
    PDF contains U3D (Universal 3D) or 3D annotation content — CVE-2011-2462 and CVE-2009-3953 are critical vulnerabilities in Adobe Reader's U3D processing that allow arbitrary code execution. U3D content in PDFs is extremely rare in normal documents.
  • ClamAV: Pdf.Dropper.Agent-1506692 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-1506692
  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • Encrypted PDF carries /JavaScript — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/JavaScript). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 1 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser exited 1. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.