Malicious PDF — malware analysis report

Static analysis result for SHA-256 e40d3c3c05a890b5…

MALICIOUS

PDF

791.7 KB Created: 2002-01-15 12:14:02 +00:00 Authoring application: Adobe-Acrobat-Distiller (via LaTeX with hyperref and thumbpdf)
MD5: c3d3dcb2d48b3cdd80e37472b0cf32b0 SHA-1: d9a93433a99758e3760ccb7cfc5f149635489e7d SHA-256: e40d3c3c05a890b5fab8a146face2986a97c45ebdf307bb2e157a60577cc0f5c
504 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment T1059.003 Windows Command Shell T1105 Ingress Tool Transfer

This PDF file contains a critical PDF_LAUNCH heuristic firing, indicating it attempts to execute a command. Specifically, it targets cmd.exe with parameters to change directory and potentially execute a dropped file. Furthermore, a critical PDF_EMBEDDED_PE_PAYLOAD firing confirms an embedded Windows executable disguised as a PDF. The PDF_LAUNCH_PLUS_DROPPER_JS heuristic indicates the use of JavaScript to facilitate this dropping action. The ClamAV detection of 'Pdf.Dropper.Agent-7316092-0' further supports its malicious nature as a dropper.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9976

Heuristics 14

  • Adobe Reader Launch action command execution critical CVE exact CVE_2010_1240
    PDF uses the Adobe Reader/Acrobat Launch action pattern associated with CVE-2010-1240: cmd.exe is invoked with attacker-controlled parameters, paired with an embedded/exported payload.
  • Launch action critical PDF_LAUNCH
    PDF contains a /Launch action whose target is an executable, URL, or UNC path — can start an external application
  • Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOAD
    PDF stream bytes contain an embedded Windows executable with a verified PE header. Exploit chains often hide droppers inside ordinary streams rather than standard /EmbeddedFile attachments.
  • /Launch action target: cmd.exe critical PDF_LAUNCH_COMMAND
    PDF /Launch action specifies an executable target with parameters '/Q /C %HOMEDRIVE%&cd %HOMEPATH%&(if exist "Desktop\\LaTeX2PDF.pdf" (cd "Desktop"' — references a known-dangerous executable (cmd, PowerShell, etc.).
  • Embedded attachment masquerades: declared document, content is windows-executable critical PDF_EMBEDDED_FILESPEC_CONTENT_MISMATCH
    An /EmbeddedFile attachment's declared filename extension or /Subtype MIME type contradicts the magic bytes of its decompressed content. The attachment is declared as a benign document or image but the bytes are an executable or executable-bearing archive. This is a deliberate deception used to hide droppers in PDF attachments and is a generic indicator of embed-and-drop weaponisation, independent of any specific CVE.
  • ClamAV: Pdf.Dropper.Agent-7316092-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7316092-0
  • /Launch action paired with attachment-dropping JS API high PDF_LAUNCH_PLUS_DROPPER_JS
    PDF combines a /Launch action with a JavaScript API call that writes or opens an attached/external resource — the canonical shape of the CVE-2010-1240 /Launch + exportDataObject family. Benign PDFs do not pair these surfaces; the combination indicates a drop-and-execute chain regardless of the specific JS API knobs or /Launch target.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85
    ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfig.org
    • http://www.ps2pdf.com/
    • http://www.glance.ch
    • http://pdf.glance.ch/eval/
    • http://www.ibnm.uni-hannover.de/
    • http://www.adobe.de/
    • http://www.adobe.de/products/acrobat/readstep.html
    • http://www.tug.org/applications/pdftex/
    • http://www.rrzn.uni-hannover.de/
    • http://www.rrzn.uni-hannover.de/pdf/
    • http://www.ctan.org/tex-archive/macros/latex/contrib/supported/hyperref/
    • http://groups.google.com/groups?hl=de&group=comp.text.tex
    • http://www.ibnm.uni-hannover.de
    • http://dionysos.mpch-mainz.mpg.de/~joeckel/howto_pdf/howto.html
    • http://www.ctan.org/tex-archive/macros/latex/contrib/supported/hyperref/doc/
    • http://www.ctan.org/tex-archive/macros/latex/contrib/supported/oberdiek/
    • http://www.ctan.org/tex-archive/support/thumbpdf/
    • http://tug.org/applications/hyperref/manual.html
    • http://w210.ub.uni-tuebingen.de/dbt/doku/dvi_ps.html
    • http://www.math.uakron.edu/~dpstory/latx2pdf.html
    • http://www.utdallas.edu/~cantrell/online/543e.html

Extracted artifacts 29

Files carved from inside the sample during analysis.

FilenameKindSourceSize
LaTeX2PDF.pdf
c6a91cba00bf87cdb064c49adaac82255cbec6fdd48fd21f9b3b96abf019916b
pdf-embedded-file PDF EmbeddedFile object 619 at offset 0x66A21 918528 bytes
javascript_obj0620_000.js
501425fa65ae7fc764bc55088a16bb2e6b201c60092d5854b2dbdc81b81fa204
pdf-javascript-stream PDF /JS object 620 at offset 0xC5956 58 bytes
stream_026_off00008deb.bin
8d077b783c854b86dd790084dc2a70f76152e3084029ec0ac6dd8f839b625c3b
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8DEB 1839447 bytes
stream_054_off0003be01.bin
fc5b00a7f946567dfe838ebbf3d9ec89973de7f345300b769b111a7beda571e5
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3BE01 798483 bytes
font_00_cff_off00048f56.bin
0c81da17553a90c1afeea6d8f3041837bca668fa958fed317e3dadce25787064
pdf-font-stream PDF embedded font (cff) at offset 0x48F56 379 bytes
font_01_cff_off000491fd.bin
4a0c98cdf909e957e8c6dc2345e8b13bb49d519fa623ebef7406218554d0cc62
pdf-font-stream PDF embedded font (cff) at offset 0x491FD 8086 bytes
font_02_cff_off0004aa8e.bin
a713a3a086d54ddebd7afca578cb7bf8b9c60d389f665cf1698782b889d9505d
pdf-font-stream PDF embedded font (cff) at offset 0x4AA8E 360 bytes
font_03_cff_off0004ad10.bin
436001bae831591b64aa3109914afb579e353839f5be20ed8d105671343185c8
pdf-font-stream PDF embedded font (cff) at offset 0x4AD10 282 bytes
font_04_cff_off0004af49.bin
045b3dc0438179a621ee8d78bc954846ed5e231baee1bda27064cf10fc285942
pdf-font-stream PDF embedded font (cff) at offset 0x4AF49 294 bytes
font_05_cff_off0004b1b7.bin
5dbf6942e85e18808b0d276dfd3e1d82eb528860cfe9f8c6864b967ee9073657
pdf-font-stream PDF embedded font (cff) at offset 0x4B1B7 592 bytes
font_06_cff_off0004b551.bin
d537b2be6297ece735f23599d17fc92461aa61ddffdbe78f755aa7ba3348269a
pdf-font-stream PDF embedded font (cff) at offset 0x4B551 2733 bytes
font_07_cff_off0004bf74.bin
e0f690561ba1d46204eb269a05cb1946275276260fca104d7a975e15fdf7fd7e
pdf-font-stream PDF embedded font (cff) at offset 0x4BF74 4355 bytes
font_08_cff_off0004ce8c.bin
ab79a56ad2d02d1038aaaa7202c767f65e1902b63e7f0dbf507512fea3592f6c
pdf-font-stream PDF embedded font (cff) at offset 0x4CE8C 2638 bytes
font_09_cff_off0004d71b.bin
f7ba8b77a3063af31180b3382339f8b8de9fc77079e7f85d828d98d537633750
pdf-font-stream PDF embedded font (cff) at offset 0x4D71B 1671 bytes
font_10_cff_off0004dcf7.bin
0ab1d234a66161bd8900c7d0b1013f0356a8da2b2cb5b1420a85d66bca1977d1
pdf-font-stream PDF embedded font (cff) at offset 0x4DCF7 297 bytes
font_11_cff_off0004dfc9.bin
54c5063298f051d65cdb3db091f432208c36bac70ddda64664188398d4973f13
pdf-font-stream PDF embedded font (cff) at offset 0x4DFC9 4266 bytes
font_12_cff_off0004eecc.bin
a5ad6468c7c307a8015cf3e64ca8fd48a9b04d684c66de64ea4d97d87aa45c77
pdf-font-stream PDF embedded font (cff) at offset 0x4EECC 9205 bytes
font_13_cff_off00050ceb.bin
5aa89dadfbe3864b50fc4a69bce30810da601806dbcbf7ce010d09283b219e7b
pdf-font-stream PDF embedded font (cff) at offset 0x50CEB 1593 bytes
font_14_cff_off000514c1.bin
8427c4807670137b893e70d25a7082dd7d24c583bf486d43ad26ddd8d6a5f9d5
pdf-font-stream PDF embedded font (cff) at offset 0x514C1 6173 bytes
font_15_cff_off000529b6.bin
4da0cb24dbbf0b507f58282359722816ec5c164e02934a4926d75edf89d7aa65
pdf-font-stream PDF embedded font (cff) at offset 0x529B6 342 bytes
font_16_cff_off00052c6e.bin
6692b88140e524622082ce39c6d5976e8471db1529b3dfd2961e483ea93db03e
pdf-font-stream PDF embedded font (cff) at offset 0x52C6E 745 bytes
font_17_cff_off000531ef.bin
f82c2794db5c62dbc707fb75aa5fce7c801556d3108433411f9ef45ce94a991e
pdf-font-stream PDF embedded font (cff) at offset 0x531EF 9592 bytes
font_18_cff_off0005506c.bin
ea1ac7abb1425e5924f6899717a5e648cd3cf4105bacbdf1355455541dc93a3e
pdf-font-stream PDF embedded font (cff) at offset 0x5506C 1593 bytes
font_19_cff_off00055858.bin
9077e0305e4206af6cb9697812780ef1734d50149c3b2ca5eb062fbad8fe9fb8
pdf-font-stream PDF embedded font (cff) at offset 0x55858 6448 bytes
font_20_cff_off00057050.bin
d31a4311b386cbd1b533cc85405c13d502ad0077a1c8786a7996492c992d83a9
pdf-font-stream PDF embedded font (cff) at offset 0x57050 10351 bytes
font_21_cff_off00059265.bin
26c6673806c24f77b7d09f8a6a4d5042b46438fbc49c002fdf336b81ce636599
pdf-font-stream PDF embedded font (cff) at offset 0x59265 4950 bytes
font_22_cff_off0005a2c8.bin
2043a0bac2aa774159ef8fbfd57501e565562072d793df520d4b115509625d7d
pdf-font-stream PDF embedded font (cff) at offset 0x5A2C8 342 bytes
font_23_cff_off0005a5a7.bin
a3aac0f6802977a79dc87d6ed6d55df486cc014db6d39b4540318d3d9a57124e
pdf-font-stream PDF embedded font (cff) at offset 0x5A5A7 4733 bytes
font_24_cff_off0005b5c9.bin
e57740e06f7d9413d37a2125a9c70642dfa8de0f9b3b889e12a9fd63a53a7db1
pdf-font-stream PDF embedded font (cff) at offset 0x5B5C9 3409 bytes