Malicious PDF — malware analysis report

Static analysis result for SHA-256 d788e52e6999e1a1…

MALICIOUS

PDF

519.1 KB Created: 2010-02-23 12:29:53 -08:00 Authoring application: Adobe LiveCycle Designer ES 8.2
MD5: bfa67a03fd7d88b9b7ebeb5cae3cd95a SHA-1: 2ec5a894f7cd73a89f442cf9a2e3b4b373392b5e SHA-256: d788e52e6999e1a162d04ebc9d211f1c1d6ca41636a97709b058d44ba2f70829
92 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript T1204.002 Malicious File

This PDF file contains multiple indicators of malicious activity, including embedded JavaScript and an embedded file payload. The ML classifier strongly flags this PDF as malicious. The embedded JavaScript, although not fully detailed here, is a common technique for downloading and executing further stages of an attack. The presence of an embedded file further supports the payload delivery mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9969

Heuristics 8

  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/pdf/1.3/
    • http://www.w3.org/1999/xhtml
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 11

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0002.bin
c06dcd026a7ea0536b63e07ce688691b585339a3ab7ff59065e546b56308c7bb
pdf-embedded-file PDF EmbeddedFile object 2 at offset 0x56 85 bytes
embedded_file_obj0003.bin
0cae1494b9c99505bf126e683a1a8be36bc8d5e793ab829e266d6e2fd62ccac3
pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x108 1466 bytes
embedded_file_obj0004.bin
2a32b795694ecd903c06e4e9e9e5cd364f40573db50dc71f1494f007925ee41f
pdf-embedded-file PDF EmbeddedFile object 4 at offset 0x3C7 6915 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
embedded_file_obj0006.bin
226eeacc5eecef2a05ca480f144ff6936594e20b5c7672e8f29f25c8bea65a56
pdf-embedded-file PDF EmbeddedFile object 6 at offset 0x19E9 2928 bytes
embedded_file_obj0007.bin
4cb349134bdb5f1a1c03281df9b53128ebe947f235398a912a4f0a9f638b24d5
pdf-embedded-file PDF EmbeddedFile object 7 at offset 0x1D56 200 bytes
embedded_file_obj0008.bin
d51b9fc28b592405fb598e711d1495e1421571073bc2e8542d55389768716c06
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x1E49 835 bytes
embedded_file_obj0009.bin
e65f1e07bc965092b3153e64a1e8777a909cc47a98c0e2a10d38c47def2e6652
pdf-embedded-file PDF EmbeddedFile object 9 at offset 0x2022 291 bytes
javascript_obj0047_000.js
f574e4d51594d1a8fd22e125b109b827c437aa898edc78babb62dbb93f8744f8
pdf-javascript-stream PDF /JS object 47 at offset 0x132BA 1532 bytes
javascript_obj0048_001.js
4a1aca004cf20431c9a66dce85404a6411a54d881a6c257882260ffc972a13eb
pdf-javascript-stream PDF /JS object 48 at offset 0x134A5 870 bytes
javascript_obj0049_002.js
826c5622c798d67e5281cca7e05933dddc90ccdcb0a6177c9f7d06f11bef8f7f
pdf-javascript-stream PDF /JS object 49 at offset 0x135FF 2795 bytes
stream_003_off00001821.bin
f47c3dc8c4eeb64abc2cc332be719add15af6ce6dfdcdb477c08a1aefdbe7477
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1821 11740 bytes