Malicious PDF — malware analysis report

Static analysis result for SHA-256 deced4cce1d281c7…

MALICIOUS

PDF

12.8 KB
MD5: f39e68bdba18c6eedc4b672e796bf228 SHA-1: e9da5b680f88a3c8f272ebeb1b823ddb303f0eab SHA-256: deced4cce1d281c715bcbe663e88a82f63c3df3baecef6a8469c775c00263525
138 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.002 Malicious File T1059.001 PowerShell T1059.003 Windows Command Shell T1059.007 JavaScript

The PDF file contains embedded JavaScript that exploits the CVE-2007-5659 vulnerability, specifically targeting the Collab.collectEmailInfo function. The heuristics indicate that this JavaScript is used to launch further stages, likely downloading and executing additional malicious content. The presence of deobfuscated JavaScript files suggests a downloader or exploit loader.

Heuristics 5

  • Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659
    PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (identified after JavaScript deobfuscation)
  • ClamAV: Pdf.Exploit.Agent-36064 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36064
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
a5c8f0f722df4dd9876a0087e1eee65bd3020c5995f94f6729f7e17f3f3677a0
pdf-javascript-stream PDF /JS object 7 at offset 0x19D 331 bytes
legacy_pdfkit_stage_000.js
8a6a324725b5e932e388037612bfad06c03dec076e26dda9c9beaac497d29362
deobfuscated-js repeated-marker hex decoded JavaScript at offset 0x2F2 12042 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
legacy_pdfkit_stage_001.js
484af08898b2f0b74cc284635a43601a27293072b58d6b1841a0e64ad0c95dd9
deobfuscated-js repeated-marker hex decoded JavaScript at offset 0x2F2 4929 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 5 eval/decoder/string-building token(s).