Malicious PDF — malware analysis report

Static analysis result for SHA-256 de1db6bc787c4c02…

MALICIOUS

PDF

311.6 KB Created: 2008-01-05 16:25:50 +01:00 Authoring application: LaTeX with hyperref package (via pdfeTeX-1.21a)
MD5: 8dc092bab9e58e64419658fb749ec8f2 SHA-1: b1592a404d82e4318601301abb75221029bc5f4b SHA-256: de1db6bc787c4c02d6a7655f5f200422ebd402ca6498289177bf1c14f104368b
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript and references to 3D content, triggering heuristics related to PDF JavaScript actions and potential U3D exploits. The embedded JavaScript is likely responsible for executing malicious code. The presence of external URIs suggests a potential download or redirection mechanism. The document body contains references to 'Laurana.u3d' and URLs associated with research institutions, which may be used as lures.

Heuristics 7

  • U3D/3D content in PDF — Adobe Reader 3D parser CVE-family indicator high CVE related PDF_U3D_CVE_RELATED
    PDF contains U3D (Universal 3D) or 3D annotation content — CVE-2011-2462 and CVE-2009-3953 are critical vulnerabilities in Adobe Reader's U3D processing that allow arbitrary code execution. U3D content in PDFs is extremely rare in normal documents.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser exited 1. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://vcg.isti.cnr.it)/S/URI/Type/Action
    • http://meshlab.sourceforge.net)/S/URI/Type/Action
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/pdfx/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://vcg.isti.cnr.it
    • http://meshlab.sourceforge.net

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0015_000.js
cd80b4bc3939d3e35f6f83c0a063c06b3ef9b580ba638b1d06f89092472b89c2
pdf-javascript-stream PDF /JS object 15 at offset 0x665 2625 bytes
stream_009_off000228bd.bin
27626e742ac2002ee573e9e201f9341c83c3a99f115cf63a3a249020aee3e653
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x228BD 177792 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.72, consistent with packed or encrypted content.
font_00_type1_off0001bcfa.bin
d129a586d7449f3004ab2629e1b01753002037f8ca955d68339aba6fea13d9dd
pdf-font-stream PDF embedded font (type1) at offset 0x1BCFA 6428 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.55, consistent with packed or encrypted content.
font_01_type1_off0001d595.bin
6d68a200ddadd677e7031f9795a017ce42b4d7f02b68d39a072ecbc1e20fb5d6
pdf-font-stream PDF embedded font (type1) at offset 0x1D595 7849 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.64, consistent with packed or encrypted content.
font_02_type1_off0001f461.bin
cab7a46a0f2b73639fc37aa221b515da6888b096748ee89dec2f4876e25f7f1f
pdf-font-stream PDF embedded font (type1) at offset 0x1F461 2374 bytes
font_03_type1_off0001fc52.bin
f1d06dc0327817e03d778a88f65436557134c269106fbc5438dd4ef0c897a441
pdf-font-stream PDF embedded font (type1) at offset 0x1FC52 11287 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.76, consistent with packed or encrypted content.