Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4613387d6c0176e…

MALICIOUS

PDF

265.8 KB Created: 2005-11-10 15:27:08 +02:00 Authoring application: Acrobat PDFMaker 7.0 for Excel (via Acrobat Distiller 7.0 (Windows))
MD5: 3cf66f15528e861a39960655ad8b8724 SHA-1: 4c606d5526497a92a1a4ee69006d9d0def7d261a SHA-256: e4613387d6c0176e0bfd6f130c9aa4a3daba6c67bc786ffa1264a54d24ad30ea
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript T1204.002 Malicious JavaScript

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The deobfuscated JavaScript code (`generic_stage_recovery_000.js`) appears to be designed to download and execute a second-stage payload, a common technique for malware delivery. The presence of external URI references to 'www.pdfill.com' further supports this. The script's complexity and obfuscation suggest malicious intent.

Machine Learning

  • Nyx PDF Classifier clean score 0.0301

Heuristics 6

  • Generic recovered JavaScript exploit stage high PDF_GENERIC_STAGE_RECOVERY
    Bounded static stage recovery exposed hidden JavaScript through generic transforms such as null-byte collapse, percent decoding, marker replacement, arithmetic character codes, fromCharCode, numeric arrays, numeric-array minus-key decoders, alphabet-index arrays, /Producer half-difference metadata arrays, hex literals, marker-stripped Base64 literals, custom 6-bit XOR table decoders, or repeated-marker hex carriers. This rule is emitted only when the recovered stage contains exploit-like Acrobat JavaScript or shellcode markers.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.pdfill.com
    • http://www.pdfill.com)/S/URI
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/pdfx/1.3/
    • http://www.iec.ch

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0001_000.js
6a1e71ee23b0fe3e492fd04299c2bd8b5aabf8b9e6d063523e3a2d3e08339ae4
pdf-javascript-stream PDF /JS object 1 at offset 0xF 2637 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
generic_stage_recovery_000.js
6de34c563aa8f9002f51ab87ac605547fb6b0d5d896c962e8dace4af7cafcca9
deobfuscated-js generic stage recovery split-literal-normalize from JavaScript object 1 at offset 0xF 2634 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
generic_stage_recovery_001.js
c686dad754a24008e7ecad3d612f22de0c535d87fefe6586bfdceb829fb9bf33
deobfuscated-js generic stage recovery null-collapse -> marker-bbbbbbbb-to-%u from decompressed stream at 0x7E1F at offset 0x7E1F 1218 bytes
icc_00_off0003981b.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x3981B 3144 bytes
font_00_sfnt_off00007e1f.bin
195a27e670c6e0b8b7dbcf792a887cfa389403d4184d0b2a7c53b6383fc0521a
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E1F 21392 bytes
font_01_sfnt_off00009e7b.bin
f65184fc63ce46829852f1227bc0f1b5d4675a3e420d5887c9a5e7c4cddbfbab
pdf-font-stream PDF embedded font (sfnt) at offset 0x9E7B 23016 bytes