Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1efe0998288d4bf…

MALICIOUS

PDF

258.3 KB Created: 2011-06-30 15:13:40 +08:00 Authoring application: Adobe InDesign CS2 (4.0) (via Adobe PDF Library 7.0) First seen: 2013-08-21
MD5: ab84a914c0f18d8375695a103258a46d SHA-1: 50f0f7b49e86a1f88c30b6443ca97595f8ee2ea0 SHA-256: e1efe0998288d4bf100d477efc5538b2f6cf4ad706f7b0b6c5fc132da17765ed
246 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded JavaScript and RichMedia content, with a critical heuristic firing for an embedded PDF child. The PDF_IMAGE_LURE heuristic indicates a phishing attempt using a screenshot-like image to hide a clickable element. The embedded JavaScript contains a URL that appears to be a lure for a software update, likely to download a secondary payload. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9349

Heuristics 10

  • Embedded PDF child has suspicious static findings critical PDF_EMBEDDED_CHILD_STATIC_TRIAGE
    PDF contains an embedded PDF stream whose extracted child matches suspicious or malicious PDF heuristics. Wrapper PDFs are commonly used to hide the actual exploit or lure payload from scanners that do not recursively inspect attachments.
  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector (matched inside decoded stream)
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 37 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic (matched inside decoded stream)
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.monotype.comMonotype In extracted file (stream_027_off0003000f.bin)
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/g/img/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://ns.adobe.com/xdp/In extracted file (embedded_file_obj0001.bin)
    • http://www.xfa.org/schema/xci/2.8/In extracted file (embedded_file_obj0002.bin)
    • http://www.xfa.org/schema/xfa-template/2.8/In extracted file (embedded_file_obj0003.bin)
    • http://www.xfa.org/schema/xfa-data/1.0/In extracted file (embedded_file_obj0004.bin)
    • http://www.xfa.org/schema/xfa-locale-set/2.7/In extracted file (embedded_file_obj0005.bin)
    • http://ns.adobe.com/xtd/In extracted file (embedded_file_obj0006.bin)
    • http://www.xfa.org/schema/xfa-form/2.8/In extracted file (embedded_file_obj0008.bin)
    • http://www.monotype.com/html/mtname/ms_arial.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlIn extracted file (stream_027_off0003000f.bin)
    • http://www.iec.chIn extracted file (icc_00_off00022acb.icc)

Extracted artifacts 23

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0001.bin pdf-embedded-file PDF EmbeddedFile object 1 at offset 0x380F 163 bytes
SHA-256: 2bbe69c5e9b01e09ead01d39980623115955d79663f86ee38c3e26d62468aede
embedded_file_obj0002.bin pdf-embedded-file PDF EmbeddedFile object 2 at offset 0x38FF 1683 bytes
SHA-256: 2db2fcfa6c7f0b58af35cd0b7a546eab3e22594fa9e6a322d8448248c1371742
embedded_file_obj0003.bin pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x3C21 784 bytes
SHA-256: 6824595d40fe37ff3a17665623abb424df29f2bf3924106e83b1192a2fc6fa0d
embedded_file_obj0004.bin pdf-embedded-file PDF EmbeddedFile object 4 at offset 0x3E15 150 bytes
SHA-256: 720c47f19e6a058099295d18a16b7149cc73fe497eb78821ea810f3192228dc4
embedded_file_obj0005.bin pdf-embedded-file PDF EmbeddedFile object 5 at offset 0x3EE6 2955 bytes
SHA-256: c8a82f67dfd8d68c2f8fe494ca2deee4604701c8f02863bf87d222b992e45de9
embedded_file_obj0006.bin pdf-embedded-file PDF EmbeddedFile object 6 at offset 0x4260 200 bytes
SHA-256: 4cb349134bdb5f1a1c03281df9b53128ebe947f235398a912a4f0a9f638b24d5
embedded_file_obj0007.bin pdf-embedded-file PDF EmbeddedFile object 7 at offset 0x4353 835 bytes
SHA-256: 41b90835819d2fc9adfbed1f624b97daf557be436627d29ad24fdfcbedc74198
embedded_file_obj0008.bin pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x452B 56 bytes
SHA-256: 4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1
embedded_file_obj0072.bin pdf-embedded-file PDF EmbeddedFile object 72 at offset 0x7E20 162 bytes
SHA-256: 676abdf89259991bbde6a57a2423c629870a437bc477a903574eba3570861622
embedded_file_obj0073.bin pdf-embedded-file PDF EmbeddedFile object 73 at offset 0x7F10 96 bytes
SHA-256: b646c863068dd809ba1fe5481aecb499465f1bd3a044f7733fe3d3935e312efb
javascript_obj0075_000.js pdf-javascript-stream PDF /JS object 75 at offset 0x7FF5 44 bytes
SHA-256: b4c77449deb96f0bd59c15743f54f9192b3b7e5a2f49d6a129eb783aa7e7d78f
Preview script
First 1,000 lines of the extracted script
app.alert("                              ");
stream_002_off000003d6.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3D6 1363 bytes
SHA-256: 529357503ec67b623d2a12816cdeea62bd639f2b4ff4e568b01c96cc3f5bfc6f
stream_003_off000005b3.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5B3 902 bytes
SHA-256: e985b5df65c8c3cf732a9074b575fbc594c1c7f0bccc0994182ec7e5c0f7308a
objstm_0041_00.bin pdf-objstm-decoded PDF /ObjStm 41 0 obj (inflated) 1575 bytes
SHA-256: cc0d110077f81314ac59a491675430d25faa86bdc2526ed35971cf361ac83464
stream_006_off000088d4.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x88D4 38286 bytes
SHA-256: ded940b77b9a3e0e4eaa9475cad5e9eb88e987a0b7ab9f46cb752799f3aca6c4
stream_027_off0003000f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3000F 80383 bytes
SHA-256: bfaaf1b95946a1027df5b0a1ba0e23d0b19cd5c16a5a752ebe2faacf0b9756a1
objstm_0016_00.bin pdf-objstm-decoded PDF /ObjStm 16 0 obj (inflated) 967 bytes
SHA-256: 3cbf19b006091b3e421e5c1cd1c8127430c1fddb99de414cc59098dfd09ec272
icc_00_off00022acb.icc pdf-icc-profile PDF ICC profile at offset 0x22ACB 3144 bytes
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
font_00_sfnt_off0002352e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2352E 38175 bytes
SHA-256: dc454725c4a9fca320b8babb04fd0239504596aa7377fffd25ad22b0f2e70f49
font_01_sfnt_off00027f48.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x27F48 65482 bytes
SHA-256: e88ea077b0370cbac92345e0f0b73bc58a2b3c32c40c360faffd6d8fa0d1de17
font_02_cff_off0002f60a.bin pdf-font-stream PDF embedded font (cff) at offset 0x2F60A 2638 bytes
SHA-256: a27259c10aa5ebff8f9541ad3b503267cb0f23811e124146ed39b9f1465e59d0
polyglot_child_pdf_off0001fbf5.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x1FBF5 134424 bytes
SHA-256: 67bd64f28004bd363fd75e1d90f2ffb27a82e0249e855223d9e8345cbeda7b65
polyglot_child_pdf_off0003f120.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x3F120 6125 bytes
SHA-256: 0b1c923c8a0028794f3a3244dc498786746334f394e41678cc58ffbeb707d0a8