PDF static analysis report

Static analysis result for SHA-256 bf2fa88c6249424c…

SUSPICIOUS

PDF

32.4 KB Created: 2011-04-12 19:13:42 -04:00 Authoring application: Writer (via OpenOffice.org 2.4) First seen: 2012-10-28
MD5: 34dbf1f66db50f14d8b86f412dbed062 SHA-1: 42e5e7b7bfcdeeb68c37ebbd7ad132bbfc114975 SHA-256: bf2fa88c6249424c093469a9aef533a797607275d749c8e92c5add9b5e3e9d3d
56 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment

The ML classifier strongly indicates maliciousness (0.998662). The PDF contains embedded files, suggesting it's a dropper or part of a multi-stage attack. The presence of XFA forms and AcroForm buttons with action triggers are common techniques for PDF-based malware delivery. No specific family could be identified.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9987

Heuristics 4

  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/ In PDF document text
    • http://www.xfa.org/schema/xci/1.0/In PDF document text
    • http://ns.adobe.com/xtd/In PDF document text
    • http://www.xfa.org/schema/xfa-data/1.0/In PDF document text
    • http://ns.adobe.com/xfdf/In PDF document text
    • http://www.xfa.org/schema/xfa-form/2.8/In PDF document text

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0020.bin pdf-embedded-file PDF EmbeddedFile object 20 at offset 0x4685 28437 bytes
SHA-256: 7ff824a563a2b43c61b874cabfab0bd467fe6c0ae256cc0b04987c28b500efe8
embedded_file_obj0018.bin pdf-embedded-file PDF EmbeddedFile object 18 at offset 0x79EE 84 bytes
SHA-256: d81baa73e490e4cb879e13927cacd1dd1be37524a37eac51603e15117c578777
embedded_file_obj0019.bin pdf-embedded-file PDF EmbeddedFile object 19 at offset 0x7AA0 228 bytes
SHA-256: 24c130f03a4cf51d470b536e94c1e58af67665739e200e0ce198ad41086243c0
embedded_file_obj0021.bin pdf-embedded-file PDF EmbeddedFile object 21 at offset 0x7B91 199 bytes
SHA-256: c97e0522381d6196cc0695f35f4d065f15c9c86a9601a7f776c6afd3f4c6b460
embedded_file_obj0022.bin pdf-embedded-file PDF EmbeddedFile object 22 at offset 0x7C82 119 bytes
SHA-256: 846dfecc0c93797cb6db4301f6af323fffd76ffdf8c053c439495412785138e7
embedded_file_obj0023.bin pdf-embedded-file PDF EmbeddedFile object 23 at offset 0x7D3A 77 bytes
SHA-256: e6c26a3478346d27e841ad49868ebf68bf4c6863b6750e8d60bda3c4c6f79876
embedded_file_obj0024.bin pdf-embedded-file PDF EmbeddedFile object 24 at offset 0x7DE1 56 bytes
SHA-256: 92a3ce61d783e15932b5de127ce45a9b4c2f98f4da2453f65241573c1dda808a