Malicious PDF — malware analysis report

Static analysis result for SHA-256 cc22ec033ef8db4e…

MALICIOUS

PDF

22.4 KB
MD5: 2853ca47e9e88511be03cf76f2dd8c9f SHA-1: 62b6f2d5c9e758260a28664501a6a575196835ad SHA-256: cc22ec033ef8db4e6ea05bf94be1f4ca85970cbbaaff3caedba0ebe3ae2fe380
118 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.001 Malicious Link T1071.001 Web Protocols T1204 User Execution

The PDF file contains embedded JavaScript that leverages the CVE-2007-5659 vulnerability through the `collab.collectEmailInfo` function. This JavaScript is obfuscated and uses `eval()` to execute, indicating it's designed to download and run a secondary payload. The presence of multiple JavaScript streams and deobfuscated stages further supports this. The primary attack vector is likely user interaction with the malicious PDF, leading to exploit execution.

Heuristics 5

  • Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659
    PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (identified after JavaScript deobfuscation)
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj111711_000.js
39f15df9eb5efd5224faa493088900eaebcb56418fcc846e7f9f793ff68e3d6e
pdf-javascript-stream PDF /JS object 111711 at offset 0x18E 3487 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 5 long base64-like blob(s).
javascript_obj111712_001.js
d29069eb79ec9717d0666f2e00371adc2f9c58f7dda180c4fca9fa9506caa95a
pdf-javascript-stream PDF /JS object 111712 at offset 0xF63 17508 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 5 long base64-like blob(s).
javascript_obj111713_002.js
2837a710da3af4c4f6231e0feb5e984a7cf0561d6fde765b064d3044fd6156cc
pdf-javascript-stream PDF /JS object 111713 at offset 0x53FD 1404 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 5 long base64-like blob(s).
legacy_pdfkit_stage_000.js
6a71fe04d9f1e9a3f90c4b70ff84c50da961115beee28510bef672a68ec30c65
deobfuscated-js multi-marker percent-array decoded JavaScript at offset 0xF63 1474 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s).
legacy_pdfkit_stage_001.js
66201566cb7b94b96d78c07e61c80e11578b5125ea85cc864e3cc788698af3dd
deobfuscated-js multi-marker percent-array decoded JavaScript at offset 0x53FD 79 bytes
legacy_pdfkit_stage_002.js
d5d5921cd83f724d12f7d10577d9138013bb083c59cef4b80b0945db73172222
deobfuscated-js multi-marker percent-array combined decoded JavaScript at offset 0xF63 1554 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s).