Malicious PDF — malware analysis report

Static analysis result for SHA-256 dd4e4ed4566f362b…

MALICIOUS

PDF

6.21 MB Created: 2009-10-12 06:41:39 +02:00 Authoring application: Writer (via OpenOffice.org 3.0)
MD5: 652ce8f3345aad8b30f5b146495a56ba SHA-1: ccb95531d567afcf0865e50d7878b94a818b4846 SHA-256: dd4e4ed4566f362b64da5f47ae94e3fb7957d760912b0bf5263219dea3d5a4e9
118 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript T1204.002 Malicious Link/URL

The PDF file contains embedded JavaScript and triggers a critical vulnerability (CVE-2009-4324) related to media playback. The presence of JavaScript actions and an unescape() call suggests the script is obfuscated and intended to perform malicious actions, such as downloading a second-stage payload. The document body was unreadable, but the heuristics strongly indicate an exploit attempt.

Heuristics 6

  • media.newPlayer — CVE-2009-4324 critical CVE exact CVE_2009_4324
    PDF JavaScript calls media.newPlayer — CVE-2009-4324 is a use-after-free in Adobe Reader's multimedia plugin triggered by media.newPlayer(). Actively exploited as a zero-day in December 2009. (matched in decompressed stream)
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits (matched inside decoded stream)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0042_000.js
d7aad5875647eb6df3ee524498ff69adff203c7fc0cb263f0b31d6dbd0cef82f
pdf-javascript-stream PDF /JS object 42 at offset 0x635BF9 2029 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s).
font_00_sfnt_off00632123.bin
31c49a24dd5020db53f01cb099abacf5c076da11ce6d6282539ef84033e39b28
pdf-font-stream PDF embedded font (sfnt) at offset 0x632123 10020 bytes