Malicious PDF — malware analysis report

Static analysis result for SHA-256 dc3833b29077df9c…

MALICIOUS

PDF

444.2 KB Authoring application: Viraciregavi
MD5: 5547f507c5c0110514229e169cf7fb50 SHA-1: 5e0db116608d67e34379f7b85f2aca1113419878 SHA-256: dc3833b29077df9c52ac11eacdfc78993990d08da4e54c20ccdd094c7cd45384
158 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious Link

The PDF file contains embedded JavaScript and exploits known vulnerabilities (CVE-2009-0927 and CVE-2007-5659) related to Acrobat API aliases. The heuristic firings indicate that the document attempts to leverage these vulnerabilities to execute code. The presence of a JavaScript file named 'legacy_pdfkit_stage_000.js' further suggests a multi-stage attack. The 'SE_CALLBACK_LURE' heuristic indicates a potential callback phishing or tech-support scam pretext.

Heuristics 7

  • Collab.getIcon — CVE-2009-0927 critical CVE exact CVE_2009_0927
    PDF JavaScript calls Collab.getIcon — CVE-2009-0927 is a stack buffer overflow in Adobe Reader triggered by Collab.getIcon() with a crafted argument. Allows arbitrary code execution. (identified after JavaScript deobfuscation)
  • Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659
    PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (identified after JavaScript deobfuscation)
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.InsiderSoftware.com/fontlist/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 9

Files carved from inside the sample during analysis.

FilenameKindSourceSize
legacy_pdfkit_stage_000.js
9c33c9ab64bb3440b9f04b04907f8b138b976c1946b92e723714f7519c8d4a17
deobfuscated-js string-concatenation normalized Acrobat API aliases at offset 0x0 567 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
icc_00_off000416ed.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x416ED 3144 bytes
font_00_sfnt_off00003752.bin
5f96e1e90c4ef56487c91d02c05141dca0967f8e2bbd5d67be6c4f381f0afa79
pdf-font-stream PDF embedded font (sfnt) at offset 0x3752 62160 bytes
font_01_sfnt_off0000cba8.bin
b661c2e877dd6b7625208ae148d736aedb24eda2d4f014262cbb7f958f538ca0
pdf-font-stream PDF embedded font (sfnt) at offset 0xCBA8 71216 bytes
font_02_sfnt_off00019c03.bin
8b62f203a4ab5c2ac76368029c584b4fa12fffc17f3b6e4e43a9997416807d21
pdf-font-stream PDF embedded font (sfnt) at offset 0x19C03 11156 bytes
font_03_sfnt_off0001bbb4.bin
d375c22ace40f0b973d7308d85023b2e0e49d40dc51da45552d116868346475e
pdf-font-stream PDF embedded font (sfnt) at offset 0x1BBB4 37232 bytes
font_04_sfnt_off00022a0b.bin
afeb9e1e920aae3aca3f295f1bbccba46b16423dac14b1b5fde4b661de9198cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x22A0B 46764 bytes
font_05_sfnt_off0002b286.bin
95592346b00d039686aa3d7e22eae3d52b011e7e842a5c123f73e89ea766cd35
pdf-font-stream PDF embedded font (sfnt) at offset 0x2B286 22628 bytes
font_06_sfnt_off0003731f.bin
6cf6df6beee88aa138f821122d0c1969b348cebe09cafe5b5f6a7eb8c27107a0
pdf-font-stream PDF embedded font (sfnt) at offset 0x3731F 32640 bytes